VYPR

rpm package

opensuse/jq&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/jq&distro=openSUSE%20Tumbleweed

Vulnerabilities (24)

  • CVE-2023-50268MedDec 13, 2023
    affected < 1.7.1-1.1fixed 1.7.1-1.1

    jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.

  • CVE-2023-50246MedDec 13, 2023
    affected < 1.7.1-1.1fixed 1.7.1-1.1

    jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.

  • CVE-2016-4074HigMay 6, 2016
    affected < 1.6-2.9fixed 1.6-2.9

    The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

  • CVE-2015-8863CriMay 6, 2016
    affected < 1.5-3.3fixed 1.5-3.3

    Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

Page 2 of 2