# CVE-2025-5899

## Summary

- **CVE ID:** CVE-2025-5899
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-590
- **Published:** Jun 9, 2025
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

## Affected Products

- GNU — PSPP (82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb)

## References

- [CNA](https://vuldb.com/?id.311671)
- [CNA](https://vuldb.com/?ctiid.311671)
- [CNA](https://vuldb.com/?submit.586106)
- [CNA](https://savannah.gnu.org/bugs/index.php?67072)
- [CNA](https://drive.google.com/file/d/1YPJLiBzOwVTcc2FzdawYxBJWGujwqy7o/view?usp=sharing)
- [CNA](https://www.gnu.org/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._