Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-23337

Опубликовано: 21 мая 2025
Источник: redhat
CVSS3: 4.3

Описание

jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.

A flaw was found in jq, a command line JSON processor. An integer overflow can occur when attempting to assign a value using an array index of 2147483647 or when creating an array with 2147483647 elements, the maximum value for a 32-bit signed integer. This issue causes out-of-bounds memory access and results in a denial of service.

Отчет

To exploit this flaw, an attacker needs to trick a user into processing a specially crafted JSON input, allowing an attacker to trigger an integer overflow and cause a crash in jq with no other security impact. Due to these reasons, this flaw has been rated with a Moderate severity.

Меры по смягчению последствий

Do not process untrusted input with the jq command line JSON processor.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2automation-controllerFix deferred
Red Hat Ceph Storage 4jqFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10jqFixedRHSA-2025:1288205.08.2025
Red Hat Enterprise Linux 8jqFixedRHSA-2025:1061808.07.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportjqFixedRHSA-2025:1062208.07.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportjqFixedRHSA-2025:1062108.07.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportjqFixedRHSA-2025:1062008.07.2025
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnjqFixedRHSA-2025:1062008.07.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicejqFixedRHSA-2025:1062008.07.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2367807jq: jq has signed integer overflow in jv.c:jvp_array_write

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.

CVSS3: 4.3
nvd
3 месяца назад

jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.

CVSS3: 6.5
msrc
28 дней назад

Описание отсутствует

CVSS3: 4.3
debian
3 месяца назад

jq is a command-line JSON processor. In versions up to and including 1 ...

suse-cvrf
20 дней назад

Security update for jq

4.3 Medium

CVSS3