Back to Database
Status published
Low
CVE-2025-48188
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call...
Vulnerability Description
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48188
Credits & Attribution
No credits recorded in the NVD database.
References
More from GNU
View All →CVE-2025-8746
GNU libopts __strstr_sse2 memory corruption
Medium
4.8
CVE-2025-8736
GNU cflow Lexer c.c yylex buffer overflow
Medium
4.8
CVE-2025-8735
GNU cflow Lexer c.c yylex null pointer dereference
Medium
4.8
CVE-2025-8225
GNU Binutils DWARF Section dwarf.c process_debug_info memory leak
Medium
4.8
CVE-2025-8224
GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference
Medium
4.8
Affected Vendor
Affected Software
PSPP
Vulnerable Versions:
0
Timeline
Official Publish:
May 16th, 2025
Last Modified:
May 17th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L