jq is a command-line JSON processor. Version 1.7 is vulnerable to heap-based buffer overflow. Version 1.7.1 contains a patch for this issue.
{
"cwe_ids": [
"CWE-120",
"CWE-122"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50246.json"
}[
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/jqlang/jq/commit/71c2ab509a8628dbbad4bc7b3f98a64aa90d3297",
"digest": {
"line_hashes": [
"290417494101508184750408009799882806556",
"260357342676783968016454112326919417947",
"226374140861562014448004111780551132909",
"38258572163093176609235064461151454765"
],
"threshold": 0.9
},
"target": {
"file": "src/jv.c"
},
"signature_type": "Line",
"id": "CVE-2023-50246-3a1c0ce4"
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/jqlang/jq/commit/71c2ab509a8628dbbad4bc7b3f98a64aa90d3297",
"digest": {
"function_hash": "313161530875538920114687879794730925876",
"length": 464.0
},
"target": {
"file": "src/jv.c",
"function": "jvp_literal_number_literal"
},
"signature_type": "Function",
"id": "CVE-2023-50246-fe6c4298"
}
]