Buffer overflow - CVE-2016-4074
Published: May 6, 2016 / Updated: August 3, 2020
Vulnerability identifier: #VU33028
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4074
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file.
Affected software
jq (Alpine package)
openjdk8 (Alpine package)
IBM Cloud Transformation Advisor
Robotic Process Automation for Cloud Pak
openjdk8 (Alpine package)
IBM Cloud Transformation Advisor
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2016-4074
Install update from vendor's website.
jq (Alpine package) - addressed in versions 1.5-r2, 1.5-r4, 1.5-r5, 1.6_rc2-r1
openjdk8 (Alpine package) - update to 8.201.08-r0
IBM Cloud Transformation Advisor - update to 3.10.1
Robotic Process Automation for Cloud Pak - update to 21.0.6
openjdk8 (Alpine package) - update to 8.201.08-r0
IBM Cloud Transformation Advisor - update to 3.10.1
Robotic Process Automation for Cloud Pak - update to 21.0.6