PT-2025-21763 · Gnu+1 · Gnu Pspp+1

Nez

·

Published

2025-05-16

·

Updated

2025-07-17

·

CVE-2025-48188

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNU PSPP versions through 2.0.1
Description libpspp-core.a in GNU PSPP through 2.0.1 contains an incorrect call from the fill buffer function (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, resulting in a heap-based buffer over-read.
Recommendations Versions prior to 2.0.1 are affected. Update to a version later than 2.0.1 to resolve the issue.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48188

Affected Products

Debian
Gnu Pspp