Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4074

Опубликовано: 24 апр. 2016
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

Отчет

Because this vulnerability requires that an unsuspecting user parses a specially crafted malicious JSON file, or that a service that does so accepts untrusted input, and because the consequences of this flaw are limited to exhaustion of the resources available to the user with whose privileges jq parses the malicious file, Red Hat assesses this vulnerability's impact as Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8jqWill not fix
Red Hat Enterprise Linux 9jqNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)jqWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)jqWill not fix
Red Hat OpenStack Platform 8 (Liberty)jqWill not fix
Red Hat OpenStack Platform 9 (Mitaka)jqWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1329982jq: stack exhaustion via jv_dump_term() function

EPSS

Процентиль: 83%
0.01997
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

CVSS3: 7.5
nvd
около 9 лет назад

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

CVSS3: 7.5
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 9 лет назад

The jv_dump_term function in jq 1.5 allows remote attackers to cause a ...

CVSS3: 7.5
github
около 3 лет назад

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

EPSS

Процентиль: 83%
0.01997
Низкий

2.6 Low

CVSS2