CVE-2025-48188

libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
References
Configurations

No configuration.

History

19 May 2025, 13:35

Type Values Removed Values Added
Summary
  • (es) libpspp-core.a en GNU PSPP hasta 2.0.1 tiene una llamada incorrecta desde fill_buffer (en data/encrypted-file.c) a la función rijndaelDecrypt de Gnulib, lo que genera una sobrelectura del búfer basado en el montón.

16 May 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-16 21:15

Updated : 2025-05-19 13:35


NVD link : CVE-2025-48188

Mitre link : CVE-2025-48188

CVE.ORG link : CVE-2025-48188


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read