CVE-2025-47816: Critical severity gnu pspp vulnerability
Published May 10, 2025
·Updated
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxmlparseattributes out-of-bounds read, related to extra content at the end of a document.
Affected Software
2 affected components
GNU pspp<=2.0.1
GNU pspp<=2.0.1
Event History
May 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47816?
CVE-2025-47816 has a medium severity rating due to its potential for causing out-of-bounds reads.
2
How do I fix CVE-2025-47816?
To fix CVE-2025-47816, upgrade to GNU PSPP version 2.0.2 or later.
3
What is affected by CVE-2025-47816?
CVE-2025-47816 affects GNU PSPP versions up to and including 2.0.1.
4
What kind of vulnerability is CVE-2025-47816?
CVE-2025-47816 is an out-of-bounds read vulnerability related to the parsing of XML attributes.
5
What can attackers potentially exploit in CVE-2025-47816?
Attackers can exploit CVE-2025-47816 to read extra content at the end of a document, which may lead to information disclosure.