libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.
https://savannah.gnu.org/bugs/?67074
Source: Mitre, NVD
Published: 2025-05-10
Updated: 2025-05-12
Base Score: 2.6
Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:P/A:P
Severity: Low
Base Score: 4.5
Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
Severity: Medium
EPSS: 0.00013