CVE-2018-20230: Buffer Overflow
Published Dec 19, 2018
·Updated
An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function readbytesinternal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected Software
1 affected component
GNU pspp=1.2.0
Event History
Dec 19, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-20230.
2
What is the severity of CVE-2018-20230?
The severity of CVE-2018-20230 is high with a CVSS score of 7.8.
3
In which software is CVE-2018-20230 found?
CVE-2018-20230 is found in GNU PSPP version 1.2.0.
4
What is the impact of CVE-2018-20230?
The vulnerability may cause a denial of service (application crash) or have unspecified other impact.
5
Is there a fix for CVE-2018-20230?
Yes, upgrading to a version higher than 1.2.0 of GNU PSPP will fix the vulnerability.