CVE-2016-4074 describes a denial-of-service vulnerability in jq version 1.5, specifically within the jv_dump_term function. An unauthenticated remote attacker can exploit this by providing a specially crafted JSON file, leading to stack consumption and an application crash. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, resulting in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5CPE matchmatch criteria | cpe:2.3:a:jq_project:jq:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2016-4074
Aug 11, 2020The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.
May 10, 2016jq: stack exhaustion via jv_dump_term() function
Apr 24, 2016