2023-12-31
ALT-BU-2023-8507-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2023-12-13
BDU:2024-02759
Уязвимость функционального языка программирования jq, связанная с возможностью записи за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (5.5)
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2023-12-13
BDU:2024-02760
Уязвимость функционального языка программирования jq, связанная с возможностью записи за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (5.5)
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2023-12-14
Modified: 2025-04-25
Modified: 2025-04-25
CVE-2023-50246
jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
- http://www.openwall.com/lists/oss-security/2023/12/15/10
- http://www.openwall.com/lists/oss-security/2023/12/15/10
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64574
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64574
- https://github.com/jqlang/jq/commit/71c2ab509a8628dbbad4bc7b3f98a64aa90d3297
- https://github.com/jqlang/jq/commit/71c2ab509a8628dbbad4bc7b3f98a64aa90d3297
- https://github.com/jqlang/jq/security/advisories/GHSA-686w-5m7m-54vc
- https://github.com/jqlang/jq/security/advisories/GHSA-686w-5m7m-54vc
Published: 2023-12-14
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-50268
jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a patch for this issue.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
- http://www.openwall.com/lists/oss-security/2023/12/15/10
- http://www.openwall.com/lists/oss-security/2023/12/15/10
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64771
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64771
- https://github.com/jqlang/jq/commit/c9a51565214eece8f1053089739aea73145bfd6b
- https://github.com/jqlang/jq/commit/c9a51565214eece8f1053089739aea73145bfd6b
- https://github.com/jqlang/jq/pull/2804
- https://github.com/jqlang/jq/pull/2804
- https://github.com/jqlang/jq/security/advisories/GHSA-7hmr-442f-qc8j
- https://github.com/jqlang/jq/security/advisories/GHSA-7hmr-442f-qc8j