The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2016/04/24/3 | Mailing List Third Party Advisory |
https://github.com/stedolan/jq/issues/1136 | Exploit Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2016/04/24/4 | Mailing List Third Party Advisory |
https://github.com/stedolan/jq/ | Product Third Party Advisory |
https://github.com/NixOS/nixpkgs/pull/18908 | Patch Third Party Advisory |
https://github.com/hashicorp/consul/issues/10263 | Third Party Advisory |
Configurations
Information
Published : 2016-05-06 10:59
Updated : 2022-06-04 20:46
NVD link : CVE-2016-4074
Mitre link : CVE-2016-4074
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
jq_project
- jq