CVE-2022-39832 is a heap-based buffer overflow vulnerability found in PSPP 1.6.2, specifically within the read_string function in utilities/pspp-dump-sav.c, affecting various Fedora and GNU PSPP distributions. This vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity, and could lead to a denial of service or potentially other unspecified impacts like arbitrary code execution. While the EPSS score is very low, suggesting a minimal likelihood of exploitation, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on the KEV catalog. Furthermore, there is no evidence of active exploitation or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.2CPE matchmatch criteria | cpe:2.3:a:gnu:pspp:1.6.2:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.