CVE-2017-12959: High severity gnu pspp vulnerability
Published Aug 18, 2017
·Updated
There is a reachable assertion abort in the function dictaddmrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
Affected Software
1 affected component
GNU pspp=0.11.0
Event History
Aug 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12959?
CVE-2017-12959 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-12959?
To fix CVE-2017-12959, upgrade to GNU PSPP version 1.0.1 or later.
3
What kind of attack can be executed using CVE-2017-12959?
An attacker can exploit CVE-2017-12959 to cause a remote denial of service by reaching an assertion abort.
4
Which versions of GNU PSPP are affected by CVE-2017-12959?
CVE-2017-12959 affects GNU PSPP versions prior to 1.0.1, including version 0.11.0.
5
Where can I find more information about CVE-2017-12959?
For more information about CVE-2017-12959, refer to the official bug tracking and support forums.