Download
| Alert*
oval:org.secpod.oval:def:1600412
jq is installed oval:org.secpod.oval:def:704515 jq is installed oval:org.secpod.oval:def:1800492 Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service via a long JSON-encoded number, which triggers a heap-based buffer overflow. oval:org.secpod.oval:def:1800493 jq is installed oval:org.secpod.oval:def:1600411 A heap-based buffer overflow flaw was found in the tokenadd function. By tricking a victim into processing a specially crafted JSON file, an attacker could use this flaw to crash jq or, potentially, execute arbitrary code on the victim"s system oval:org.secpod.oval:def:1800974 The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service via a crafted JSON file. oval:org.secpod.oval:def:1800977 The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service via a crafted JSON file. oval:org.secpod.oval:def:1800978 The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service via a crafted JSON file. oval:org.secpod.oval:def:1800979 The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service via a crafted JSON file. oval:org.secpod.oval:def:1900485 The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service via a crafted JSON file. |