Description
A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3675-1 | zbar security update |
Debian DSA |
DSA-5614-1 | zbar security update |
Github GHSA |
GHSA-mhp6-jvpx-2p4m | Heap-based buffer overflow in ZBar |
Ubuntu USN |
USN-7118-1 | ZBar vulnerabilities |
References
History
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T18:16:43.280Z
Reserved: 2023-08-22T00:00:00.000Z
Link: CVE-2023-40889
No data.
Status : Modified
Published: 2023-08-29T17:15:12.840
Modified: 2025-11-04T19:15:56.193
Link: CVE-2023-40889
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN