CVE-2017-12961: Input Validation
Published Aug 18, 2017
·Updated
There is an assertion abort in the function parseattributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
Affected Software
1 affected component
GNU pspp=0.11.0
Event History
Aug 18, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12961?
CVE-2017-12961 is classified as a denial of service vulnerability that can lead to crashes and service disruptions.
2
How do I fix CVE-2017-12961?
To fix CVE-2017-12961, upgrade to GNU PSPP version 1.0.1 or later, which addresses this vulnerability.
3
What causes CVE-2017-12961?
CVE-2017-12961 is caused by an assertion abort in the parse_attributes() function in the libpspp library.
4
Which versions of GNU PSPP are affected by CVE-2017-12961?
GNU PSPP versions prior to 1.0.1, including version 0.11.0, are affected by CVE-2017-12961.
5
Can CVE-2017-12961 be exploited remotely?
Yes, CVE-2017-12961 allows for remote denial of service through crafted input that triggers the vulnerability.