CVE-2017-10792: Null Pointer Dereference
Published Jul 2, 2017
·Updated
There is a NULL Pointer Dereference in the function llinsert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.
Affected Software
1 affected component
GNU pspp=0.10.5-pre2
Event History
Jul 2, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10792?
CVE-2017-10792 is classified as a high-severity vulnerability due to the potential for remote denial of service attacks.
2
How do I fix CVE-2017-10792?
To fix CVE-2017-10792, upgrade to GNU PSPP version 0.11.0 or later.
3
What type of vulnerability is CVE-2017-10792?
CVE-2017-10792 is a NULL Pointer Dereference vulnerability.
4
What impact does CVE-2017-10792 have on affected software?
CVE-2017-10792 can cause the software to crash when processing invalid SPSS data.
5
Which versions of GNU PSPP are affected by CVE-2017-10792?
GNU PSPP versions before 0.11.0, specifically 0.10.5-pre2, are affected by CVE-2017-10792.