Gnu · Pspp · CVE-2018-20230
**Name of the Vulnerable Software and Affected Versions**
PSPP version 1.2.0
**Description**
A heap-based buffer overflow issue exists in the `read bytes internal` function located in `utilities/pspp-dump-sav.c`. This issue can be exploited by attackers to cause a denial of service, resulting in an application crash, or potentially have other unspecified impacts.
**Recommendations**
For PSPP version 1.2.0, as a temporary workaround, consider disabling the `read bytes internal` function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.