oss-sec mailing list archives
CVE Request: jq: stack exhaustion using jv_dump_term() function
From: Gustavo Grieco <gustavo.grieco () gmail com>
Date: Sun, 24 Apr 2016 10:44:39 +0200
Hi, A crash caused by stack exhaustion parsing a JSON was found. It affects, at least version 1.5 as well as the last git revision. Technical details and a reproducer are available here: https://github.com/stedolan/jq/issues/1136 This crash was found by QuickFuzz working with Radamsa (that caused the extreme mutation) Regards, Gustavo.
Current thread:
- CVE Request: jq: stack exhaustion using jv_dump_term() function Gustavo Grieco (Apr 24)
- Re: CVE Request: jq: stack exhaustion using jv_dump_term() function cve-assign (Apr 24)