CVE-2016-4074Allocation of Resources Without Limits or Throttling in Project JQ

Severity
7.5HIGHNVD
EPSS
1.3%
top 20.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 6
Latest updateMay 13

Description

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debianjqlang/jq< 1.5+dfsg-1.1+3
NVDjq_project/jq1.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-63w9-2p7c-mwwp: The jv_dump_term function in jq 12022-05-13
CVEList
CVE-2016-4074: The jv_dump_term function in jq 12016-05-06
OSV
CVE-2016-4074: The jv_dump_term function in jq 12016-05-06

📋Vendor Advisories

4
Ubuntu
jq vulnerability2021-03-15
Microsoft
The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.2016-05-10
Red Hat
jq: stack exhaustion via jv_dump_term() function2016-04-24
Debian
CVE-2016-4074: jq - The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of...2016

💬Community

4
Bugzilla
CVE-2016-4074 jq: stack exhaustion via jv_dump_term() function [fedora-all]2016-04-25
Bugzilla
CVE-2016-4074 jq: stack exhaustion via jv_dump_term() function2016-04-25
Bugzilla
CVE-2016-4074 jq: stack exhaustion via jv_dump_term() function [epel-6]2016-04-25
Bugzilla
CVE-2016-4074 jq: stack exhaustion via jv_dump_term() function [epel-7]2016-04-25
CVE-2016-4074 — JQ Project JQ vulnerability | cvebase