CVE-2025-47815: Buffer Overflow
Published May 10, 2025
·Updated
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflateread (called indirectly from zipmemberreadall) in zip-reader.c.
Affected Software
2 affected components
GNU pspp<2.0.1
GNU pspp<=2.0.1
Event History
May 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-47815?
CVE-2025-47815 is considered a high-severity vulnerability due to its potential for heap-based buffer overflow exploitation.
2
How do I fix CVE-2025-47815?
To fix CVE-2025-47815, upgrade GNU PSPP to version 2.0.1 or later, which addresses this vulnerability.
3
What are the potential impacts of CVE-2025-47815?
The potential impacts of CVE-2025-47815 include application crashes, data corruption, and the possibility of remote code execution.
4
What specific component is affected by CVE-2025-47815?
CVE-2025-47815 affects the libpspp-core.a component in GNU PSPP, specifically in the inflate_read function.
5
Who is at risk from CVE-2025-47815?
Users and administrators running vulnerable versions of GNU PSPP prior to 2.0.1 are at risk from CVE-2025-47815.