CVE-2016-4074: High severity ubuntu jq vulnerability
Published May 6, 2016
·Updated
The jvdumpterm function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6rc1-r0.
Affected Software
2 affected componentsFixes available
debian/jq
1.6-2.11.7.1-3
Jq Project Jq<=1.5
Remediation
Patch Available
Patch Available
Event History
May 6, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4074?
CVE-2016-4074 is classified as a denial of service vulnerability that allows for stack consumption and application crash.
2
How do I fix CVE-2016-4074?
To fix CVE-2016-4074, upgrade jq to version 1.6_rc1-r0 or later.
3
What versions of jq are affected by CVE-2016-4074?
CVE-2016-4074 affects jq versions up to and including 1.5.
4
Can CVE-2016-4074 be exploited remotely?
Yes, CVE-2016-4074 can be exploited remotely via a crafted JSON file.
5
What is the impact of CVE-2016-4074?
The impact of CVE-2016-4074 is a denial of service condition resulting from a stack overflow.