CVE-2025-5001

LOW

GNU PSPP <82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb - Integer Overflow

Title source: llm

Description

A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 3.3
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Classification

CWE
CWE-190 CWE-189
Status published

Affected Products (1)

gnu/pspp

Timeline

Published May 20, 2025
Tracked Since Feb 18, 2026