Your message dated Wed, 06 Aug 2025 06:33:53 +0000
with message-id <[email protected]>
and subject line Bug#806960: fixed in stardict 3.0.7+git20220909+dfsg-7
has caused the Debian Bug report #806960,
regarding Stardict leaking user data in default configuration.
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
806960: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806960
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: stardict
Version: 3.0.1-9.2
Severity: normal

Hi,

"stardict" program in default configuration have by default enabled
plugin "Dict.cn 1.0". This plugin sends every searched word by a plain
HTTP to a server dict.cn. Translated sentence is send even if local
dictionary of local central European language is used and even if
"Enable Network dictionaries" in setting is disabled.

Disabling plugin itself help, however this is not intuitive.
It is not evident that plugins ignore setting from a main settings menu,
a user is not noticed about sending a data in any way.

After years of using stardict, I became aware of this privacy leakage
just after warning from a friend analyzing network traffic.
People who enabled automatic translation of clipboard content
have their password send in plaintext over the network,
when they use a password manager. (I know about at least one such person)

Problematic behavior of stardict in default setting have been (not)
solved repeatedly, I think both reports are related to this plugin:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=613236
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731

Stardict version seems to be the same in all debian versions,
from wheezy to sid.

I suggest disabling "Dict.cn" plugin in a default configuration.

cheers,
n.


-- System Information:
Debian Release: 7.9
  APT prefers oldoldstable
  APT policy: (500, 'oldoldstable'), (500, 'oldstable')
Architecture: i386 (i686)

Kernel: Linux 3.2.0-2-686-pae (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages stardict depends on:
ii  stardict-gtk  3.0.1-9.2

stardict recommends no packages.

stardict suggests no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: stardict
Source-Version: 3.0.7+git20220909+dfsg-7
Done: xiao sheng wen <[email protected]>

We believe that the bug you reported is fixed in the latest version of
stardict, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
xiao sheng wen <[email protected]> (supplier of updated stardict package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 06 Aug 2025 14:09:39 +0800
Source: stardict
Architecture: source
Version: 3.0.7+git20220909+dfsg-7
Distribution: unstable
Urgency: medium
Maintainer: xiao sheng wen <[email protected]>
Changed-By: xiao sheng wen <[email protected]>
Closes: 806960
Changes:
 stardict (3.0.7+git20220909+dfsg-7) unstable; urgency=medium
 .
   * d/stardict-plugin.install:not install stardict_dictdotcn.so, Closes: 
#806960
   * d/rules:Added --disable-dictdotcn option, dictdotcn is not provid server 
now
Checksums-Sha1:
 3eda4c693c46b60a7e98348897e096005cf9c487 3088 
stardict_3.0.7+git20220909+dfsg-7.dsc
 ba5259492697c6028e173965c8550a23545a9252 23060 
stardict_3.0.7+git20220909+dfsg-7.debian.tar.xz
 2b0636b4abf16491708ef032ed3172c82585d5f5 18336 
stardict_3.0.7+git20220909+dfsg-7_source.buildinfo
Checksums-Sha256:
 90b112a16ae047425a407a5795ad819ee9217ae3878b601f17261445f570f3fd 3088 
stardict_3.0.7+git20220909+dfsg-7.dsc
 e5ab1c54a4f1b1b578ec8d38cfcf4e6b469112a08398136fba7b95d618c836bd 23060 
stardict_3.0.7+git20220909+dfsg-7.debian.tar.xz
 dd36ec4ddeae47cfc719cf0d8ff1f9194984f6441ff2b3c4afc59c2a96a210b3 18336 
stardict_3.0.7+git20220909+dfsg-7_source.buildinfo
Files:
 fd39018c4f3e186165f12811a2728558 3088 utils optional 
stardict_3.0.7+git20220909+dfsg-7.dsc
 76baf0e8f7c07185388deb8d3ac7fd59 23060 utils optional 
stardict_3.0.7+git20220909+dfsg-7.debian.tar.xz
 df357acc03a9c98b7aa8d6fc798833f5 18336 utils optional 
stardict_3.0.7+git20220909+dfsg-7_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEvGv7H5NUQYeSuhtTJ2Egg8PSprAFAmiS83YACgkQJ2Egg8PS
prA/zQ/9G44dsR1NdnqMJQKL8x4mDm2c9duMqZe+UgADjOvdpOzcx92VLKMy5+//
X/WGZUQBonzVxZjdOl+FXsNd8vBED6zypS4x/KozLdo903S5qcLnwUuqQWbMJPDu
uOvkheMyYzE45PDe7fwzrKJ97jW6ZfFGWvCt/P4CmE+/l/cVrTtL/RdVvzJr/5NO
U73F90fD+MsjdTruRyU7Kel9WKJpLXeusxJ6r6ccdOUg2z/TAuL2lsbDbmw6gE3B
kQ2I6cPPeQGpAP7zismZgldr2ugRTgueOMvGVRiRP759L7xdC6aBcjuBVhk/lvWC
8XmgQ1jT/9vGccXRZ1K4opK6Q520AnoBV7Y9vz/C58AHYzNyHAsnHVfK8++XnGuL
NWQCJhunNrnFSUfnoLr32GYb9o4yFvQWqpwogzb9ft2k33A+gQNEOJa1wDQwAshK
KvBKVwvNqoIQhkeuC3/qicCS642fsZNvGzEyXSmJ2wJZKrNAD4/PCd08J2up5A8s
hqDt0G5Jc3uk8yFF9YTt4/GaNGMwVRNSVueYT6BRCvJfteR5lfdHDoOnJsjikN3T
QdRMJeGu4FufEZ0vxpNHYWFVFZo76LtaVh3cRW9gfScfnjNCoE0ol7QvhJhliVrI
76VlBWyTBZ3IvlSq3CmLX5UgNpvI/IlLYk4uCWTbQu8B2HHn460=
=2bwy
-----END PGP SIGNATURE-----

Attachment: pgp2H_t8b0SkL.pgp
Description: PGP signature


--- End Message ---

Reply via email to