First published: Fri Aug 18 2017(Updated: )
There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU PSPP | =0.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12959 is classified as a denial of service vulnerability.
To fix CVE-2017-12959, upgrade to GNU PSPP version 1.0.1 or later.
An attacker can exploit CVE-2017-12959 to cause a remote denial of service by reaching an assertion abort.
CVE-2017-12959 affects GNU PSPP versions prior to 1.0.1, including version 0.11.0.
For more information about CVE-2017-12959, refer to the official bug tracking and support forums.