Candidate: CVE-2018-20230 PublicDate: 2018-12-19 11:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20230 https://bugzilla.redhat.com/show_bug.cgi?id=1660318 Description: An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_pspp: upstream_pspp: released (1.2.0-3) precise/esm_pspp: DNE trusty_pspp: ignored (reached end-of-life) trusty/esm_pspp: DNE (trusty was needs-triage) xenial_pspp: ignored (end of standard support, was needed) bionic_pspp: needed cosmic_pspp: ignored (reached end-of-life) disco_pspp: ignored (reached end-of-life) eoan_pspp: ignored (reached end-of-life) focal_pspp: DNE groovy_pspp: not-affected (1.2.0-5) hirsute_pspp: not-affected (1.2.0-5) impish_pspp: not-affected (1.2.0-5) jammy_pspp: not-affected (1.2.0-5) devel_pspp: not-affected (1.2.0-5)