Описание
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
A heap-based buffer overflow flaw was found in jq's tokenadd() function. By tricking a victim into processing a specially crafted JSON file, an attacker could use this flaw to crash jq or, potentially, execute arbitrary code on the victim's system.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 8 | jq | Not affected | ||
Red Hat Enterprise Linux 9 | jq | Not affected | ||
Red Hat OpenStack Platform 9 (Mitaka) | jq | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | jq | Fixed | RHSA-2016:1098 | 23.05.2016 |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | jq | Fixed | RHSA-2016:1099 | 23.05.2016 |
Red Hat OpenStack Platform 8.0 (Liberty) | jq | Fixed | RHSA-2016:1106 | 25.05.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.4 Medium
CVSS2
Связанные уязвимости
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
Off-by-one error in the tokenadd function in jv_parse.c in jq allows r ...
EPSS
4.4 Medium
CVSS2