[Git][security-tracker-team/security-tracker][master] Add CVE-2024-53427/jq

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Feb 27 21:15:15 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
54076c69 by Salvatore Bonaccorso at 2025-02-27T22:14:55+01:00
Add CVE-2024-53427/jq

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -915,7 +915,8 @@ CVE-2025-0719 (IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerabl
 CVE-2024-6810 (The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross- ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2024-53427 (jq v1.7.1 contains a stack-buffer-overflow in the decNumberCopy functi ...)
-	TODO: check
+	- jq <unfixed>
+	NOTE: https://github.com/jqlang/jq/issues/3196
 CVE-2024-52925 (In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution ca ...)
 	NOT-FOR-US: OPSWAT MetaDefender Kiosk
 CVE-2024-47053 (This advisory addresses an authorization vulnerability in Mautic's HTT ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/54076c69b39ab3094562f0494d2f3d5d09133f5c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/54076c69b39ab3094562f0494d2f3d5d09133f5c
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250227/22fdcfbb/attachment.htm>


More information about the debian-security-tracker-commits mailing list