Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-49355 status ? #2986

Closed
z00z00z00 opened this issue Dec 13, 2023 · 2 comments
Closed

CVE-2023-49355 status ? #2986

z00z00z00 opened this issue Dec 13, 2023 · 2 comments

Comments

@z00z00z00
Copy link

CVE-2023-49355
linzc21 published [1] an one-byte oob write affecting JQ 1.7-37-g88f01a7 (88f01a7).

[1] https://github.com/linzc21/bug-reports/blob/main/reports/jq/1.7-37-g88f01a7/heap-buffer-overflow/CVE-2023-49355.md

JQ status
The researcher did not provide any information about potential report to you. I create this bug report to have some status. Do you confirm this issue ? Is so, any available patch ?

Thanks in advance.
z00

@emanuele6
Copy link
Member

We call it CVE-2023-50246
I told that user their report was a duplicate, but they already published it anyway even before reporting it to us. :(
We have had a patch ready for a while.
I am organising to get 1.7.1 released soon (maybe today?); we're currently waiting to get a CVE number for another vulnerability.

@emanuele6 emanuele6 closed this as not planned Won't fix, can't repro, duplicate, stale Dec 13, 2023
@z00z00z00
Copy link
Author

OK, got it. Thanks Emanuele

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants