Описание
Security update for jq
jq was updated to fix one security issue.
This security issue was fixed:
- CVE-2015-8863: Heap buffer overflow in tokenadd() function (boo#976992).
Список пакетов
openSUSE Leap 42.1
jq-1.5-7.1
libjq-devel-1.5-7.1
libjq1-1.5-7.1
Ссылки
- E-Mail link for openSUSE-SU-2016:1214-1
- SUSE Security Ratings
Описание
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
Затронутые продукты
openSUSE Leap 42.1:jq-1.5-7.1
openSUSE Leap 42.1:libjq-devel-1.5-7.1
openSUSE Leap 42.1:libjq1-1.5-7.1
Ссылки
- CVE-2015-8863
- SUSE Bug 1014176
- SUSE Bug 976992