CVE-2025-53964

NameCVE-2025-53964
DescriptionGoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary and then searches for any term included in that dictionary.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
goldendict (PTS)bullseye1.5.0~rc2+git20200409+ds-2vulnerable
bookworm1.5.0~rc2+git20221126+ds-1vulnerable
goldendict-ng (PTS)sid, trixie25.06.0-2undetermined

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
goldendictsource(unstable)(unfixed)
goldendict-ngsource(unstable)undetermined

Notes

https://github.com/tigr78/CVE-2025-53964
check more on details of vulnerability

Search for package or bug name: Reporting problems