Logo
vulnerabilityCVE-2024-23337
Name
CVE-2024-23337
Source
NVD ( link)Debian ( link)
Description
jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. Commit de21386681c0df0104a99d9d09db23a9b2a78b1e contains a patch for the issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
jq
Patched

Vulnerability Ratings#


4.3
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.7.1
Patched
buildroot
master
1.8.1
Not Affected
openwrt
master
1.8.1-r2
Not Affected
openwrt
openwrt-25.12
1.8.1-r2
Not Affected
yocto
kirkstone
1.6+gitX
Patched
yocto
master
1.8.1
Not Affected

Resolved with patches#


jq (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix signed integer overflow in jvp_array_write and jvp_object_rehash
=?utf-8?b?IkNoYW5nWmh1byBDaGVuICjpmbPmmIzlgKwpIg==?=
CVE-2024-23337

jq (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix signed integer overflow in jvp_array_write and
itchyny <itchyny@cybozu.co.jp>
CVE-2024-23337

jq (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix signed integer overflow in jvp_array_write and
itchyny <itchyny@cybozu.co.jp>
CVE-2024-23337