A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-zbar | Aug 22, 2024 | Aug 29, 2023 | |
| Amazon_linux | — | amazon-linux-upgrade-zbar | Dec 5, 2023 | Aug 29, 2023 |
| Debian | debian-upgrade-zbar | Dec 4, 2023 | Aug 29, 2023 | |
| Suse | — | suse-upgrade-libzbar-develsuse-upgrade-libzbar0suse-upgrade-libzbar0-32bitsuse-upgrade-libzbarqt-develsuse-upgrade-libzbarqt0suse-upgrade-libzbarqt0-32bitsuse-upgrade-zbar | Dec 22, 2023 | Aug 29, 2023 |
| Ubuntu | ubuntu-pro-upgrade-libzbar0 | Nov 22, 2024 | Aug 29, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub