PT-2022-25023 · Pspp+1 · Pspp+1

Han Zheng

+1

·

Published

2022-09-05

·

Updated

2022-10-01

·

CVE-2022-39832

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PSPP version 1.6.2
Description An issue was discovered that allows attackers to cause a denial of service or possibly have other unspecified impacts due to a heap-based buffer overflow at the read string function in utilities/pspp-dump-sav.c.
Recommendations For PSPP version 1.6.2, consider disabling the read string function in utilities/pspp-dump-sav.c as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-39832

Affected Products

Debian
Pspp