--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-583e4098b9
2024-01-18 01:24:42.646391
--------------------------------------------------------------------------------

Name        : zbar
Product     : Fedora 38
Version     : 0.23.93
Release     : 1.fc38
URL         : https://zbar.sourceforge.net/
Summary     : Bar code reader
Description :
ZBar Bar Code Reader is an open source software suite for reading bar
codes from various sources, such as video streams, image files and raw
intensity sensors. It supports EAN-13/UPC-A, UPC-E, EAN-8, Code 128,
Code 93, Code 39, Codabar, Interleaved 2 of 5, QR Code and SQ Code.

--------------------------------------------------------------------------------
Update Information:

0.23.93, fixes for two CVEs
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jan  9 2024 Gwyn Ciesla  - 0.23.93-1
- 0.23.93
* Fri Jan  5 2024 Florian Weimer  - 0.23.90-12
- Add missing Py_SIZE to py311.patch
* Sat Jul 22 2023 Fedora Release Engineering  - 0.23.90-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Fri Jul  7 2023 Michael J Gruber  - 0.23.90-10
- Fix FTBFS with python 3.12 (rhbz#2220630)
* Thu Jun 15 2023 Python Maint  - 0.23.90-9
- Rebuilt for Python 3.12
* Wed Mar  1 2023 Gwyn Ciesla  - 0.23.90-8
- migrated to SPDX license
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2235860 - CVE-2023-40890 zbar: stack overflow caused malicious qr code may lead to information diusclosure or arbitrary code execution. [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2235860
  [ 2 ] Bug #2235863 - CVE-2023-40889 zbar: buffer overflow via crafted qr code [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2235863
  [ 3 ] Bug #2257396 - Affect by  CVE-2023-40889
        https://bugzilla.redhat.com/show_bug.cgi?id=2257396
  [ 4 ] Bug #2257428 - zbar-0.23.93 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2257428
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-583e4098b9' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
--
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 38: zbar 2024-583e4098b9

January 18, 2024
0.23.93, fixes for two CVEs

Summary

ZBar Bar Code Reader is an open source software suite for reading bar

codes from various sources, such as video streams, image files and raw

intensity sensors. It supports EAN-13/UPC-A, UPC-E, EAN-8, Code 128,

Code 93, Code 39, Codabar, Interleaved 2 of 5, QR Code and SQ Code.

Update Information:

0.23.93, fixes for two CVEs

Change Log

* Tue Jan 9 2024 Gwyn Ciesla - 0.23.93-1 - 0.23.93 * Fri Jan 5 2024 Florian Weimer - 0.23.90-12 - Add missing Py_SIZE to py311.patch * Sat Jul 22 2023 Fedora Release Engineering - 0.23.90-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Fri Jul 7 2023 Michael J Gruber - 0.23.90-10 - Fix FTBFS with python 3.12 (rhbz#2220630) * Thu Jun 15 2023 Python Maint - 0.23.90-9 - Rebuilt for Python 3.12 * Wed Mar 1 2023 Gwyn Ciesla - 0.23.90-8 - migrated to SPDX license

References

[ 1 ] Bug #2235860 - CVE-2023-40890 zbar: stack overflow caused malicious qr code may lead to information diusclosure or arbitrary code execution. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2235860 [ 2 ] Bug #2235863 - CVE-2023-40889 zbar: buffer overflow via crafted qr code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2235863 [ 3 ] Bug #2257396 - Affect by CVE-2023-40889 https://bugzilla.redhat.com/show_bug.cgi?id=2257396 [ 4 ] Bug #2257428 - zbar-0.23.93 is available https://bugzilla.redhat.com/show_bug.cgi?id=2257428

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-583e4098b9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
Name : zbar
Product : Fedora 38
Version : 0.23.93
Release : 1.fc38
URL : https://zbar.sourceforge.net/
Summary : Bar code reader

Related News