VYPR

rpm package

opensuse/jq&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/jq&distro=openSUSE%20Tumbleweed

Vulnerabilities (25)

  • CVE-2024-53427HigFeb 26, 2025
    affected < 1.7.1-3.1fixed 1.7.1-3.1

    decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter of .-. when the input ha

  • CVE-2023-50268MedDec 13, 2023
    affected < 1.7.1-1.1fixed 1.7.1-1.1

    jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.

  • CVE-2023-50246MedDec 13, 2023
    affected < 1.7.1-1.1fixed 1.7.1-1.1

    jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.

  • CVE-2016-4074HigMay 6, 2016
    affected < 1.6-2.9fixed 1.6-2.9

    The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

  • CVE-2015-8863CriMay 6, 2016
    affected < 1.5-3.3fixed 1.5-3.3

    Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

Page 2 of 2