Candidate: CVE-2017-10791 PublicDate: 2017-07-02 03:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10791 https://bugzilla.redhat.com/show_bug.cgi?id=1467004 Description: There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack. Ubuntu-Description: Notes: sbeattie> fixed upstream in 41c6f5447941e5d36d0554ba874671649353752f Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=866890 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_pspp: upstream: http://git.savannah.gnu.org/cgit/pspp.git/commit/?id=41c6f5447941e5d36d0554ba874671649353752f upstream_pspp: released (1.0.0-1) precise/esm_pspp: DNE trusty_pspp: ignored (reached end-of-life) trusty/esm_pspp: DNE (trusty was needed) vivid/ubuntu-core_pspp: DNE xenial_pspp: ignored (end of standard support, was needed) yakkety_pspp: ignored (reached end-of-life) zesty_pspp: ignored (reached end-of-life) artful_pspp: DNE bionic_pspp: not-affected (1.0.1-1) cosmic_pspp: not-affected (1.0.1-1) disco_pspp: not-affected (1.0.1-1) eoan_pspp: not-affected (1.0.1-1) focal_pspp: DNE groovy_pspp: not-affected (1.0.1-1) hirsute_pspp: not-affected (1.0.1-1) impish_pspp: not-affected (1.0.1-1) jammy_pspp: not-affected (1.0.1-1) devel_pspp: not-affected (1.0.1-1)