CVE-2023-50268: jq has stack-based buffer overflow in decNaNs
Published Dec 13, 2023
·Updated
jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.
Affected Software
1 affected component
jqlang jq=1.7
Remediation
Patch Available
Patch Available
Event History
Dec 13, 2023
CVE Published
08:49 PM
Data Sourced
08:49 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-50268?
CVE-2023-50268 is classified as a high severity vulnerability due to the potential for stack-based buffer overflow.
2
How do I fix CVE-2023-50268?
To fix CVE-2023-50268, upgrade jq from version 1.7 to version 1.7.1 or later, which contains the necessary patch.
3
What software is affected by CVE-2023-50268?
CVE-2023-50268 affects jq version 1.7 that is built with decNumber support.
4
What type of vulnerability is CVE-2023-50268?
CVE-2023-50268 is a stack-based buffer overflow vulnerability.
5
Is there a public disclosure for CVE-2023-50268?
Yes, CVE-2023-50268 has been publicly disclosed in security mailing lists and issue trackers.