Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mhp6-jvpx-2p4m: Heap-based buffer overflow in ZBar

A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

ghsa
#vulnerability#git#buffer_overflow

Skip to content

    • Actions

      Automate any workflow

    • Packages

      Host and manage packages

    • Security

      Find and fix vulnerabilities

    • Codespaces

      Instant dev environments

    • Copilot

      Write better code with AI

    • Code review

      Manage code changes

    • Issues

      Plan and track work

    • Discussions

      Collaborate outside of code

    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
  • Pricing
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2023-40889

Heap-based buffer overflow in ZBar

Moderate severity GitHub Reviewed Published Aug 29, 2023 to the GitHub Advisory Database • Updated Aug 30, 2023

Affected versions

<= 0.23.90

Description

A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-40889
  • https://hackmd.io/@cspl/B1ZkFZv23

Published to the GitHub Advisory Database

Aug 29, 2023

Last updated

Aug 30, 2023

Related news

Debian Security Advisory 5614-1

Debian Linux Security Advisory 5614-1 - Two vulnerabilities were discovered in zbar, a library for scanning and decoding QR and bar codes, which may result in denial of service, information disclosure or potentially the execution of arbitrary code if a specially crafted code is processed.

CVE-2023-40889: ZBar Heap-based Buffer Overflow Vulnerability - HackMD

A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

CVE-2023-40889: ZBar Heap-based Buffer Overflow Vulnerability - HackMD

A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.