Upstream information

CVE-2025-47229 at MITRE

Description

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.

CVSS v3 Scores
  CNA (MITRE) National Vulnerability Database SUSE
Base Score 2.9 5.5 2.9
Vector CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector Local Local Local
Attack Complexity High Low High
Privileges Required None Low None
User Interaction None None None
Scope Unchanged Unchanged Unchanged
Confidentiality Impact None None None
Integrity Impact None None None
Availability Impact Low High Low
CVSSv3 Version 3.1 3.1 3.1
SUSE Bugzilla entry: 1242838 [NEW]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Sat May 3 06:00:20 2025
CVE page last modified: Sat Jul 19 12:33:16 2025