StarDict sends X11 clipboard to remote servers
StarDict is a
GPLv3-licensed cross-platform dictionary application. It includes dictionaries
for a number of languages, and has a rich plugin ecosystem. It also has a
glaring security problem: while running on X11, using Debian's default configuration,
it will send a user's text selections over unencrypted HTTP to two remote servers.
On AugustĀ 4, Vincent Lefevre
reported the problem to the oss-security mailing list and to
Debian's bug tracker.
He identified it while testing his setup before the
...
Read more at lwn.net