PT-2018-15297 · Gnu+2 · Pspp+2

Seri0Us

·

Published

2018-12-19

·

Updated

2025-03-27

·

CVE-2018-20230

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PSPP version 1.2.0
Description A heap-based buffer overflow issue exists in the read bytes internal function located in utilities/pspp-dump-sav.c. This issue can be exploited by attackers to cause a denial of service, resulting in an application crash, or potentially have other unspecified impacts.
Recommendations For PSPP version 1.2.0, as a temporary workaround, consider disabling the read bytes internal function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-4697
CVE-2018-20230
OPENSUSE-SU-2019:0198-1
OPENSUSE-SU-2019:0240-1
OPENSUSE-SU-2019_0198-1
OPENSUSE-SU-2019_0212-1
OPENSUSE-SU-2024:11199-1

Affected Products

Alt Linux
Pspp
Suse