Описание
jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
jq | fixed | 1.8.1-1 | package | |
jq | not-affected | trixie | package | |
jq | not-affected | bookworm | package | |
jq | not-affected | bullseye | package |
Примечания
https://github.com/jqlang/jq/security/advisories/GHSA-rmjp-cr27-wpg2
Introduced with: https://github.com/jqlang/jq/commit/4003202ccf241cedb01cbe5f81523bcc40d588ad (jq-1.8.0)
Fixed by: https://github.com/jqlang/jq/commit/499c91bca9d4d027833bc62787d1bb075c03680e
EPSS
Связанные уязвимости
jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.
jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.
jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.
Уязвимость функции f_strflocaltime() функционального языка программирования jq, позволяющая нарушителю оказать воздействие на доступность защищаемой информации
EPSS