CVE-2025-55174

low

Description

In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the end, because of use of QIODevice::ReadWrite instead of QODevice::WriteOnly.

References

https://kde.org/info/security/advisory-20250811-1.txt

https://invent.kde.org/utilities/skanpage/-/commit/de3ad2941054a26920e022dc7c4a3dc16c065b5a

https://github.com/KDE/skanpage/tags

Details

Source: Mitre, NVD

Published: 2025-11-26

Updated: 2025-12-01

Risk Information

CVSS v2

Base Score: 1.2

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3.2

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Severity: Low

EPSS

EPSS: 0.00011