CVE-2025-48188
published 2025-05-16CVE-2025-48188: libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.14%
3.8th percentile
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pspp | — | — |
| gnu | pspp | <= 2.0.1 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-48188: libpspp-core
osv·2025-05-16·CVSS 5.5
CVE-2025-48188 [MEDIUM] CVE-2025-48188: libpspp-core
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
GHSA
GHSA-x4wp-4w98-53c5: libpspp-core
ghsa_unreviewed·2025-05-16
CVE-2025-48188 [LOW] CWE-125 GHSA-x4wp-4w98-53c5: libpspp-core
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
Debian
CVE-2025-48188: pspp - libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer ...
vendor_debian·2025·CVSS 2.9
CVE-2025-48188 [LOW] CVE-2025-48188: pspp - libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer ...
libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
2025-05-16
Published