REDHAT-BUG-2367807: Integer Overflow
jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2367807?
REDHAT-BUG-2367807 has a denial of service impact due to an integer overflow in jq versions up to and including 1.7.1.
How do I fix REDHAT-BUG-2367807?
To fix REDHAT-BUG-2367807, update jq to version 1.7.2 or later.
Which versions of jq are affected by REDHAT-BUG-2367807?
jq versions up to and including 1.7.1 are affected by REDHAT-BUG-2367807.
What causes the vulnerability identified as REDHAT-BUG-2367807?
The vulnerability REDHAT-BUG-2367807 is caused by an integer overflow when assigning values using a maximum index.
Is there a patch for REDHAT-BUG-2367807?
Yes, a patch for REDHAT-BUG-2367807 is included in commit de21386681c0df0104a99d9d09db23a9b2a78b1e.