216.73.216.233

CVE-2025-5001

· Published 20/05/2025 22:15 · Modified 21/05/2025 20:24

Labels: CVE-2025-5001 2025-05-20CVE-2025-5001CWE-189[email protected]

Essential information

Published
20/05/2025 22:15
Modified
21/05/2025 20:24
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gnu / pspp cpe:2.3:a:gnu:pspp:*:*:*:*:*:*:*:*

References