Integer Overflow Vulnerability in GNU PSPP Affects Data Conversion
CVE-2017-10791
6.5MEDIUM
Summary
An integer overflow vulnerability exists in the hash_int function of the libpspp library found in GNU PSPP prior to version 0.11.0. This flaw can be exploited when handling malformed SPSS data, resulting in a remote denial of service attack. By providing specially crafted input, an attacker can cause the library to crash during the data conversion process from SPSS to CSV format, disrupting services that rely on this functionality.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved