First published: Sun Oct 18 2015(Updated: )
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE Leap | =42.1 | |
openSUSE openSUSE | =13.2 | |
Jq Project Jq | <=1.5 | |
debian/jq | <=1.5+dfsg-1<=1.4-2.1 | |
debian/jq | 1.6-2.1 1.7.1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.