Hi team,

We are evaluating GNU PSPP and would like to seek clarification regarding
several reported vulnerabilities associated with PSPP version 2.1.1.

For convenience, we have attached a spreadsheet containing the relevant CVE
references and descriptions.

Could you please advise on the following:

   1. Whether these vulnerabilities are confirmed and applicable to the
   current PSPP releases.
   2. Whether a fixed version is available that addresses these
   vulnerabilities.
   3. Whether there is a recommended upgrade path.
   4. Whether any temporary mitigations or workarounds are available until
   an upgrade can be performed.
   5. Whether there is a planned release schedule that includes fixes for
   these issues.

The vulnerabilities referenced are:

   - CVE-2025-5899
   - CVE-2025-5898
   - CVE-2025-47229
   - CVE-2025-48188

Any guidance, recommendations, or references to security advisories would
be greatly appreciated.

Thank you for your assistance.

Kind regards,

Abi

Attachment: PSPP_Vulns.xlsx
Description: MS-Excel 2007 spreadsheet

Reply via email to