CVE-2025-5898

A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

10 Jun 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como crítica en GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. La función parse_variables_option del archivo utility/pspp-convert.c se ve afectada. La manipulación provoca escritura fuera de los límites. El ataque debe abordarse localmente. Se ha hecho público el exploit y puede que sea utilizado.
References () https://savannah.gnu.org/bugs/index.php?67071 - () https://savannah.gnu.org/bugs/index.php?67071 -

09 Jun 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 22:15

Updated : 2025-06-12 16:06


NVD link : CVE-2025-5898

Mitre link : CVE-2025-5898

CVE.ORG link : CVE-2025-5898


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-787

Out-of-bounds Write