jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.
{
"binaries": [
{
"binary_version": "1.6-2.1ubuntu3",
"binary_name": "jq"
},
{
"binary_version": "1.6-2.1ubuntu3",
"binary_name": "jq-dbgsym"
},
{
"binary_version": "1.6-2.1ubuntu3",
"binary_name": "libjq-dev"
},
{
"binary_version": "1.6-2.1ubuntu3",
"binary_name": "libjq1"
},
{
"binary_version": "1.6-2.1ubuntu3",
"binary_name": "libjq1-dbgsym"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "1.7.1-3build1",
"binary_name": "jq"
},
{
"binary_version": "1.7.1-3build1",
"binary_name": "jq-dbgsym"
},
{
"binary_version": "1.7.1-3build1",
"binary_name": "libjq-dev"
},
{
"binary_version": "1.7.1-3build1",
"binary_name": "libjq1"
},
{
"binary_version": "1.7.1-3build1",
"binary_name": "libjq1-dbgsym"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "1.7.1-3ubuntu1",
"binary_name": "jq"
},
{
"binary_version": "1.7.1-3ubuntu1",
"binary_name": "jq-dbgsym"
},
{
"binary_version": "1.7.1-3ubuntu1",
"binary_name": "libjq-dev"
},
{
"binary_version": "1.7.1-3ubuntu1",
"binary_name": "libjq1"
},
{
"binary_version": "1.7.1-3ubuntu1",
"binary_name": "libjq1-dbgsym"
}
],
"availability": "No subscription required"
}