PT-2023-8958 · Jq+2 · Jq+2
Emanuele6
·
Published
2023-12-13
·
Updated
2025-03-10
·
CVE-2023-50268
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
jq version 1.7
Description
The issue is related to a stack-based buffer overflow in builds using decNumber, which can allow an attacker to cause a denial of service. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations
For version 1.7, update to version 1.7.1 to resolve the issue. As a temporary workaround, consider restricting the use of decNumber in builds until a patch is applied.
Exploit
Fix
Stack Overflow
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Red Os
Jq