CVE-2018-20230: GNU Pspp

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

Affected products

  • GNU Pspp: version 1.2.0 only

Published 2018-12-19. Last modified 2026-06-17.