CVE-2025-5898

Severity CVSS v4.0:
MEDIUM
Type:
CWE-119 Buffer Errors
Publication date:
09/06/2025
Last modified:
12/06/2025

Description

A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.