CVE-2023-50246: jq has heap-buffer-overflow vulnerability in the function decToString in decNumber.c
Published Dec 13, 2023
·Updated
jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.
Affected Software
3 affected components
jqlang jq=1.7
jqlang jq=1.7-rc1
jqlang jq=1.7-rc2
Remediation
Patch Available
Event History
Dec 13, 2023
CVE Published
08:43 PM
Data Sourced
08:43 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-50246?
CVE-2023-50246 is classified as a high severity vulnerability due to the potential for a heap-based buffer overflow.
2
How do I fix CVE-2023-50246?
To fix CVE-2023-50246, upgrade jq to version 1.7.1 or later, which contains a patch for the vulnerability.
3
Which versions of jq are affected by CVE-2023-50246?
CVE-2023-50246 affects version 1.7 of jq.
4
What type of vulnerability is CVE-2023-50246?
CVE-2023-50246 is a heap-based buffer overflow vulnerability.
5
Is there a patch available for CVE-2023-50246?
Yes, a patch for CVE-2023-50246 is available in jq version 1.7.1.