CVE-2022-39831
Published on: Not Yet Published
Last Modified on: 10/01/2022 02:16:00 AM UTC
Certain versions of Fedora from Fedoraproject contain the following vulnerability:
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
- CVE-2022-39831 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[SECURITY] Fedora 36 Update: pspp-1.6.2-4.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
[SECURITY] Fedora 37 Update: pspp-1.6.2-4.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
PSPP - Bugs: bug #62977, heap-buffer-overflow in... [Savannah] | savannah.gnu.org text/html |
![]() |
Related QID Numbers
- 283119 Fedora Security Update for pspp (FEDORA-2022-ad61bb0c42)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Fedoraproject | Fedora | 36 | All | All | All |
Operating System | Fedoraproject | Fedora | 37 | All | All | All |
Application | Gnu | Pspp | 1.6.2 | All | All | All |
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*:
- cpe:2.3:a:gnu:pspp:1.6.2:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-39831 : An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_… twitter.com/i/web/status/1… | 2022-09-05 05:06:09 |
![]() |
Potentially Critical CVE Detected! CVE-2022-39831 An issue was discovered in PSPP 1.6.2. There is a heap-based buff… twitter.com/i/web/status/1… | 2022-09-05 06:56:00 |
![]() |
CVE-2022-39831 | 2022-09-05 05:38:47 |