GHSA-mhp6-jvpx-2p4m

Suggest an improvement
Source
https://github.com/advisories/GHSA-mhp6-jvpx-2p4m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-mhp6-jvpx-2p4m/GHSA-mhp6-jvpx-2p4m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mhp6-jvpx-2p4m
Aliases
Published
2023-08-29T18:31:53Z
Modified
2024-02-16T08:17:25.949262Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Heap-based buffer overflow in ZBar
Details

A heap-based buffer overflow exists in the qrreadermatch_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

References

Affected packages

PyPI / zbar

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.23.90

Affected versions

0.*

0.10