A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade zbar | Aug 22, 2024 | Aug 29, 2023 |
| Amazon_linux | — | Upgrade zbar | Dec 5, 2023 | Aug 29, 2023 |
| Debian | — | Upgrade zbar | Dec 4, 2023 | Aug 29, 2023 |
| Suse | — | Upgrade libzbar0Upgrade libzbarqt-develUpgrade libzbar0-32bitUpgrade libzbarqt0Upgrade libzbar-develUpgrade zbarUpgrade libzbarqt0-32bit | Dec 22, 2023 | Aug 29, 2023 |
| Ubuntu | — | Upgrade libzbar0 (Ubuntu Pro) | Nov 22, 2024 | Aug 29, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub