CVE-2025-5001: GNU PSPP pspp-convert.c calloc integer overflow
A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5001?
CVE-2025-5001 is considered a problematic vulnerability due to its potential for integer overflow in a critical function.
How do I fix CVE-2025-5001?
To fix CVE-2025-5001, update to the latest version of GNU PSPP that addresses this vulnerability.
What software is affected by CVE-2025-5001?
CVE-2025-5001 affects GNU PSPP specifically.
Can CVE-2025-5001 be exploited remotely?
CVE-2025-5001 requires local access to exploit the vulnerability.
What function is vulnerable in CVE-2025-5001?
The calloc function in the pspp-convert.c file is the specific point of vulnerability in CVE-2025-5001.