Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
jq 基于堆的缓冲区溢出漏洞
Vulnerability Description
jq是软件开发者Stephen Dolan所研发的一款轻量级的命令行JSON处理器。 jq的jv_parse.c文件中的‘tokenadd()’函数中存在差一错误漏洞。远程攻击者可借助特制的JSON-encoded数字利用该漏洞造成拒绝服务(应用程序崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A