Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4rg-46c3-r5vq

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

EPSS

Процентиль: 94%
0.07495
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 10 лет назад

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

redhat
почти 11 лет назад

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

CVSS3: 9.8
nvd
около 10 лет назад

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

CVSS3: 9.8
msrc
почти 6 лет назад

Описание отсутствует

CVSS3: 9.8
debian
около 10 лет назад

Off-by-one error in the tokenadd function in jv_parse.c in jq allows r ...

EPSS

Процентиль: 94%
0.07495
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-119