See https://seclists.org/oss-sec/2025/q3/75 I don't have stardict installed. Someone needs to confirm if the report is true for the version in Mageia. If it is, the application should be banned from Mageia and added to task-obsolete
CC: (none) => friQA Contact: (none) => securityComponent: RPM Packages => Security
That sounds like something that could be fixed with a patch. We've had to do the same to disable phoning home (though not to China) functionality in other packages before.
https://seclists.org/oss-sec/2025/q3/81
Summary: stardict is spyware by design => StarDict sends the user's X11 selection to the networkCVE: (none) => CVE-2025-55014
Suggested advisory: ======================== The updated package removes the YouDao plugin for StarDict, as Debian did, to fix a security vulnerability: The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP. (CVE-2025-55014) References: https://seclists.org/oss-sec/2025/q3/75 https://seclists.org/oss-sec/2025/q3/81 ======================== Updated package in core/updates_testing: ======================== stardict-3.0.6.3-2.1.mga9 from SRPM: stardict-3.0.6.3-2.1.mga9.src.rpm
Assignee: geiger.david68210 => qa-bugsCC: (none) => nicolas.salgueroStatus: NEW => ASSIGNED
Keywords: (none) => advisory
MGA9-64 server Plasma Wayland on Compaq H000SB. No installation issues. Fooled around with some English words (this is an English installation), sounds OK in my Dutch-speaking ears (you know what I mean). Tried a few Dutch words, with the sometimes strange results I expected. Good enough for me. Wait for someone with another language installed?
CC: (none) => herman.viaene
Before strace stardict write(25, "GET HTTP://dict.youdao.com/fsear"..., 173) = 173 installing stardict-3.0.6.3-2.1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################### 1/1: stardict ################################################################################################### 1/1: removing stardict-3.0.6.3-2.mga9.x86_64 ################################################################################################### I not find the "call home" line in strace looks good to me
Whiteboard: (none) => MGA9-64-OK
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0298.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED