CVE-2025-47814: Buffer Overflow
Published May 10, 2025
·Updated
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflateread (called indirectly from spvreadxmlmember) in zip-reader.c.
Affected Software
2 affected components
GNU pspp<=2.0.1
GNU pspp<=2.0.1
Event History
May 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Jan 16, 57343
Event
via FIRST·10:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-47814?
CVE-2025-47814 has been classified as having a high severity due to the potential for a heap-based buffer overflow.
2
How do I fix CVE-2025-47814?
To fix CVE-2025-47814, update GNU PSPP to version 2.0.2 or later, which addresses the vulnerability.
3
What components are affected by CVE-2025-47814?
CVE-2025-47814 affects the libpspp-core.a library in GNU PSPP versions up to and including 2.0.1.
4
What type of vulnerability is CVE-2025-47814?
CVE-2025-47814 is a heap-based buffer overflow vulnerability.
5
Can CVE-2025-47814 be exploited remotely?
Yes, CVE-2025-47814 can potentially be exploited remotely, allowing attackers to affect the application.