Out-of-Bounds Write Vulnerability in GNU PSPP by GNU
CVE-2025-5898
4.8MEDIUM
Key Information:
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-5898?
A vulnerability has been discovered in GNU PSPP within the 'parse_variables_option' function located in 'utilities/pspp-convert.c'. This vulnerability allows for out-of-bounds write manipulation, which is exploitable under local conditions. The public availability of the exploit may lead to unauthorized manipulation of system data, raising serious security concerns.
Affected Version(s)
PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.