Description
jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
4OSVCVE-2023-50246: jq is a command-line JSON processor↗2023-12-13 ▶ CVEListjq has heap-buffer-overflow vulnerability in the function decToString in decNumber.c↗2023-12-13 ▶ OSVCVE-2023-49355: decToString in decNumber/decNumber↗2023-12-11 ▶ CVEListCVE-2023-49355: decToString in decNumber/decNumber↗2023-12-11 ▶ 📋Vendor Advisories
3Red Hatjq: heap buffer overflow in function decToString() in decNumber.c↗2023-12-13 ▶ DebianCVE-2023-50246: jq - jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buf...↗2023 ▶ DebianCVE-2023-49355: jq - decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds ...↗2023 ▶