CVE-2023-40889
zbar - security update
9.8
CRITICAL
CVSS 3.1
EPSS 0.81%
Description
A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.
How to fix CVE-2023-40889
To remediate CVE-2023-40889, upgrade the affected package to a fixed version below.
- —upgrade to 0.23.90-1+deb11u1 or later
- —upgrade to 0.22-1+deb10u1 or later
- —upgrade to 0.23.90-1+deb11u1 or later
- —no fix listed
Is CVE-2023-40889 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 0.23.90-1+deb11u1
- from 0, < 0.22-1+deb10u1
- from 0, < 0.23.90-1+deb11u1
- from 0, <= 0.23.90
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |