An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function readbytesinternal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
There is a reachable assertion abort in the function writelongstringmissingvalues() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.