Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4074

Опубликовано: 24 апр. 2016
Источник: redhat
CVSS2: 2.6

Описание

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

Отчет

Because this vulnerability requires that an unsuspecting user parses a specially crafted malicious JSON file, or that a service that does so accepts untrusted input, and because the consequences of this flaw are limited to exhaustion of the resources available to the user with whose privileges jq parses the malicious file, Red Hat assesses this vulnerability's impact as Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8jqWill not fix
Red Hat Enterprise Linux 9jqNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)jqWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)jqWill not fix
Red Hat OpenStack Platform 8 (Liberty)jqWill not fix
Red Hat OpenStack Platform 9 (Mitaka)jqWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1329982jq: stack exhaustion via jv_dump_term() function

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

CVSS3: 7.5
nvd
больше 9 лет назад

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

CVSS3: 7.5
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 9 лет назад

The jv_dump_term function in jq 1.5 allows remote attackers to cause a ...

CVSS3: 7.5
github
больше 3 лет назад

The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

2.6 Low

CVSS2

Уязвимость CVE-2016-4074