CVE-2022-39831: Buffer Overflow
Published Sep 5, 2022
·Updated
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function readbytesinternal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
Affected Software
3 affected components
GNU pspp=1.6.2
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Remediation
Patch Available
Event History
Sep 5, 2022
CVE Published
via MITRE·04:12 AM
Data Sourced
via MITRE·04:12 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-39831.
2
What is the severity of CVE-2022-39831?
The severity of CVE-2022-39831 is high with a CVSS score of 7.8.
3
Which software versions are affected by CVE-2022-39831?
PSPP version 1.6.2, GNU PSPP, Fedora 36, and Fedora 37 are affected by CVE-2022-39831.
4
What is the impact of CVE-2022-39831?
CVE-2022-39831 can cause a denial of service (application crash) or possibly have unspecified other impact.
5
How can I fix CVE-2022-39831?
Apply the latest security patches or updates provided by the vendor.