Hi team, We are evaluating GNU PSPP and would like to seek clarification regarding several reported vulnerabilities associated with PSPP version 2.1.1.
For convenience, we have attached a spreadsheet containing the relevant CVE references and descriptions. Could you please advise on the following: 1. Whether these vulnerabilities are confirmed and applicable to the current PSPP releases. 2. Whether a fixed version is available that addresses these vulnerabilities. 3. Whether there is a recommended upgrade path. 4. Whether any temporary mitigations or workarounds are available until an upgrade can be performed. 5. Whether there is a planned release schedule that includes fixes for these issues. The vulnerabilities referenced are: - CVE-2025-5899 - CVE-2025-5898 - CVE-2025-47229 - CVE-2025-48188 Any guidance, recommendations, or references to security advisories would be greatly appreciated. Thank you for your assistance. Kind regards, Abi
PSPP_Vulns.xlsx
Description: MS-Excel 2007 spreadsheet
