PT-2022-25022 · Pspp+1 · Pspp+1

Han Zheng

·

Published

2022-09-05

·

Updated

2022-10-01

·

CVE-2022-39831

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PSPP version 1.6.2
Description A heap-based buffer overflow issue exists in the read bytes internal function located in utilities/pspp-dump-sav.c. This issue can be exploited by attackers to cause a denial of service, resulting in an application crash, or potentially have other unspecified impacts.
Recommendations For PSPP version 1.6.2, as a temporary workaround, consider restricting access to the read bytes internal function in utilities/pspp-dump-sav.c to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-39831

Affected Products

Debian
Pspp