CVE-2025-55174 – KDE Skanpage Uncontrolled File Truncation Vulnerability

The following table lists the changes that have been made to the
CVE-2025-55174 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Nov. 26, 2025

    Action Type Old Value New Value
    Added Description In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the end, because of use of QIODevice::ReadWrite instead of QODevice::WriteOnly.
    Added CVSS V3.1 AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
    Added CWE CWE-684
    Added Reference https://github.com/KDE/skanpage/tags
    Added Reference https://invent.kde.org/utilities/skanpage/-/commit/de3ad2941054a26920e022dc7c4a3dc16c065b5a
    Added Reference https://kde.org/info/security/advisory-20250811-1.txt
Share the Post:

Related Posts