A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade zbar | Aug 22, 2024 | Aug 29, 2023 |
| Amazon_linux | — | Upgrade zbar | Dec 5, 2023 | Aug 29, 2023 |
| Debian | — | Upgrade zbar | Dec 4, 2023 | Aug 29, 2023 |
| Suse | — | Upgrade libzbar0Upgrade libzbar-develUpgrade libzbar0-32bitUpgrade libzbarqt-develUpgrade zbarUpgrade libzbarqt0-32bitUpgrade libzbarqt0 | Dec 22, 2023 | Aug 29, 2023 |
| Ubuntu | — | Upgrade libzbar0 (Ubuntu Pro) | Nov 22, 2024 | Aug 29, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub