{"id":"MGASA-2024-0374","summary":"Updated zbar packages fix security vulnerabilities","details":"A heap-based buffer overflow exists in the qr_reader_match_centers\nfunction of ZBar 0.23.90. Specially crafted QR codes may lead to\ninformation disclosure and/or arbitrary code execution. To trigger this\nvulnerability, an attacker can digitally input the malicious QR code, or\nprepare it to be physically scanned by the vulnerable scanner.\nCVE-2023-40889\nA stack-based buffer overflow vulnerability exists in the\nlookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may\nlead to information disclosure and/or arbitrary code execution. To\ntrigger this vulnerability, an attacker can digitally input the\nmalicious QR code, or prepare it to be physically scanned by the\nvulnerable scanner. CVE-2023-40890\n","modified":"2026-04-16T04:42:18.144732688Z","published":"2024-11-27T19:59:10Z","upstream":["CVE-2023-40889","CVE-2023-40890"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0374.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33790"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7118-1"}],"affected":[{"package":{"name":"zbar","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/zbar?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.93-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0374.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}