CVE-2016-4074 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-4074): The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file.
@Maintainer please confirm if we are affected by this vulnerability. Thank you
Bug: https://github.com/stedolan/jq/issues/1136 Patch: https://github.com/stedolan/jq/commit/83e2cf607f3599d208b6b3129092fa7deb2e5292 @maintainer(s), please drop the old affected version.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=aa9d3e38d6d0763bbfe1bd2f2af686410d8ab83d commit aa9d3e38d6d0763bbfe1bd2f2af686410d8ab83d Author: Patrick McLean <patrick.mclean@sony.com> AuthorDate: 2020-03-17 18:13:10 +0000 Commit: Patrick McLean <chutzpah@gentoo.org> CommitDate: 2020-03-17 18:13:10 +0000 app-misc/jq: remove vunlerable version (bug #636382) Bug: https://bugs.gentoo.org/636382 Copyright: Sony Interactive Entertainment Inc. Package-Manager: Portage-2.3.94, Repoman-2.3.21 Signed-off-by: Patrick McLean <chutzpah@gentoo.org> app-misc/jq/Manifest | 1 - app-misc/jq/jq-1.5-r3.ebuild | 60 -------------------------------------------- 2 files changed, 61 deletions(-)
@maintainer(s): thanks for cleaning up. Tree is clean.
GLSA Vote: No Thank you all for you work. Closing as [noglsa].