From ${URL} : A vulnerability was found in jq. There was an off-by one error, as the NUL terminator byte was not allocated on resize. A maliciously crafted JSON file could cause the application to crash. External references: https://github.com/stedolan/jq/issues/995 Upstream fix: https://github.com/stedolan/jq/commit/8eb1367ca44e772963e704a700ef72ae2e12babd References(reproducer available): https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=802231 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Should be fixed https://github.com/gentoo/gentoo/commit/251e0d08bf9303fbbd2ccb66b550def65f609db5
Ebuild is already stable, no vulnerable version left in repository. New GLSA created.
This issue was resolved and addressed in GLSA 201612-20 at https://security.gentoo.org/glsa/201612-20 by GLSA coordinator Aaron Bauman (b-man).