CVE-2025-2724

CVSS 3.0 Score 5.9 of 10 (medium)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 201

Summary

CVE-2025-2724 is a newly identified vulnerability affecting GNOME libgsf versions up to 1.14.53. The issue lies in the 'sorting_key_copy' function, which can be exploited through manipulation of the 'Name' argument. This leads to an out-of-bounds read, enabling an attacker to launch an attack on the local host. Despite early disclosure, the vendor has not responded to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share