Stack Buffer Overflow in jq by JQLang
CVE-2024-53427

8.1HIGH

Key Information:

Vendor

Jqlang

Status
Vendor
CVE Published:
26 February 2025

What is CVE-2024-53427?

A stack buffer overflow vulnerability exists in the decNumberCopy function of jq v1.7.1, which could allow an attacker to exploit the overflow potentially leading to arbitrary code execution or crashes. Users of jq are advised to patch their installations to enhance security and mitigate risks associated with this issue.

Affected Version(s)

jq 0 <= 1.7.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.