MGASA-2024-0374

Source
https://advisories.mageia.org/MGASA-2024-0374.html
Import Source
https://advisories.mageia.org/MGASA-2024-0374.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0374
Related
Published
2024-11-27T19:59:10Z
Modified
2024-11-27T19:25:38Z
Summary
Updated zbar packages fix security vulnerabilities
Details

A heap-based buffer overflow exists in the qrreadermatchcenters function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner. CVE-2023-40889 A stack-based buffer overflow vulnerability exists in the lookupsequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner. CVE-2023-40890

References
Credits

Affected packages

Mageia:9 / zbar

Package

Name
zbar
Purl
pkg:rpm/mageia/zbar?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.23.93-1.mga9

Ecosystem specific

{
    "section": "core"
}