Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 39: 2024-73d5220ed3 urgent: zbar buffer overflow and memory issue

fedora
Calendar Grey January 18, 2024
Dist Fedora Esm H88
Fedora 39's zbar update addresses significant issues, including memory vulnerabilities and potential privacy infringements.
0.23.93, fixes for two CVEs

Summary

ZBar Bar Code Reader is an open source software suite for reading bar

codes from various sources, such as video streams, image files and raw

intensity sensors. It supports EAN-13/UPC-A, UPC-E, EAN-8, Code 128,

Code 93, Code 39, Codabar, Interleaved 2 of 5, QR Code and SQ Code.

Update Information:

0.23.93, fixes for two CVEs

Change Log

* Tue Jan 9 2024 Gwyn Ciesla - 0.23.93-1 - 0.23.93 * Fri Jan 5 2024 Florian Weimer - 0.23.90-12 - Add missing Py_SIZE to py311.patch

References


[ 1 ] Bug #2235860 - CVE-2023-40890 zbar: stack overflow caused malicious qr code may lead to information diusclosure or arbitrary code execution. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2235860 [ 2 ] Bug #2235863 - CVE-2023-40889 zbar: buffer overflow via crafted qr code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2235863 [ 3 ] Bug #2257396 - Affect by CVE-2023-40889 https://bugzilla.redhat.com/show_bug.cgi?id=2257396 [ 4 ] Bug #2257428 - zbar-0.23.93 is available https://bugzilla.redhat.com/show_bug.cgi?id=2257428

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-73d5220ed3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: zbar
Product: Fedora 39
Version: 0.23.93
Release: 1.fc39
URL:
Summary: Bar code reader

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here