Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3ww-vpp7-fpm5

Опубликовано: 29 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

EPSS

Процентиль: 40%
0.00177
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 2 года назад

A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

CVSS3: 9.8
nvd
почти 2 года назад

A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

CVSS3: 9.8
debian
почти 2 года назад

A stack-based buffer overflow vulnerability exists in the lookup_seque ...

CVSS3: 9.8
fstec
почти 2 года назад

Уязвимость функции lookup_sequence библиотеки чтения штрих-кодов ZBar, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

suse-cvrf
больше 1 года назад

Security update for zbar

EPSS

Процентиль: 40%
0.00177
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787