A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code execution.
| Software | From | Fixed in |
|---|---|---|
| gnu / gnu_scientific_library | 2.6 | 2.6.x |
| gnu / gnu_scientific_library | 2.5 | 2.5.x |
| debian / debian_linux | 10.0 | 10.0.x |