CVE-2025-48188: Medium severity gnu pspp vulnerability
Published May 16, 2025
·Updated
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fillbuffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
Affected Software
2 affected components
GNU pspp<=2.0.1
GNU pspp<=2.0.1
Event History
May 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48188?
CVE-2025-48188 has been classified as a high severity vulnerability due to its impact on memory safety.
2
How do I fix CVE-2025-48188?
To fix CVE-2025-48188, upgrade to the latest version of GNU PSPP that is beyond version 2.0.1.
3
What types of systems are affected by CVE-2025-48188?
CVE-2025-48188 affects systems running GNU PSPP versions up to and including 2.0.1.
4
What is the potential impact of CVE-2025-48188?
The potential impact of CVE-2025-48188 includes possible information disclosure due to a heap-based buffer over-read.
5
Is there a workaround for CVE-2025-48188 if I cannot update?
There are no official workarounds for CVE-2025-48188, the best mitigation is to update to a secure version.