Candidate: CVE-2015-8863 PublicDate: 2016-05-06 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8863 https://github.com/stedolan/jq/issues/995 https://github.com/stedolan/jq/commit/8eb1367ca44e772963e704a700ef72ae2e12babd http://www.openwall.com/lists/oss-security/2016/04/23/1 Description: Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=802231 Priority: medium Discovered-by: Assigned-to: mikesalvatore CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_jq: upstream: https://github.com/stedolan/jq/commit/8eb1367ca44e772963e704a700ef72ae2e12babd upstream_jq: released (1.5+dfsg-1.1) precise_jq: DNE precise/esm_jq: DNE trusty_jq: released (1.3-1.1ubuntu1.1) trusty/esm_jq: released (1.3-1.1ubuntu1.1) vivid/stable-phone-overlay_jq: DNE vivid/ubuntu-core_jq: DNE wily_jq: ignored (reached end-of-life) xenial_jq: released (1.5+dfsg-1ubuntu0.1) yakkety_jq: ignored (reached end-of-life) zesty_jq: ignored (reached end-of-life) artful_jq: not-affected bionic_jq: not-affected devel_jq: not-affected