Source: jq Version: 1.7-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for jq. CVE-2023-50246[0]: | jq is a command-line JSON processor. Version 1.7 is vulnerable to | heap-based buffer overflow. Version 1.7.1 contains a patch for this | issue. CVE-2023-50268[1]: | jq is a command-line JSON processor. Version 1.7 is vulnerable to | stack-based buffer overflow in builds using decNumber. Version 1.7.1 | contains a patch for this issue. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-50246 https://www.cve.org/CVERecord?id=CVE-2023-50246 https://github.com/jqlang/jq/security/advisories/GHSA-686w-5m7m-54vc [1] https://security-tracker.debian.org/tracker/CVE-2023-50268 https://www.cve.org/CVERecord?id=CVE-2023-50268 https://github.com/jqlang/jq/security/advisories/GHSA-7hmr-442f-qc8j Regards, Salvatore

