First published: Mon Sep 05 2022(Updated: )
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU PSPP | =1.6.2 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-39831.
The severity of CVE-2022-39831 is high with a CVSS score of 7.8.
PSPP version 1.6.2, GNU PSPP, Fedora 36, and Fedora 37 are affected by CVE-2022-39831.
CVE-2022-39831 can cause a denial of service (application crash) or possibly have unspecified other impact.
Apply the latest security patches or updates provided by the vendor.