{"id":"GHSA-mhp6-jvpx-2p4m","summary":"Heap-based buffer overflow in ZBar","details":"A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.","aliases":["CVE-2023-40889","PYSEC-2026-576"],"modified":"2026-06-29T12:26:52.549326405Z","published":"2023-08-29T18:31:53Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-30T20:22:19Z","nvd_published_at":"2023-08-29T17:15:12Z","cwe_ids":["CWE-122","CWE-787"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40889"},{"type":"PACKAGE","url":"https://github.com/mchehab/zbar"},{"type":"WEB","url":"https://hackmd.io/@cspl/B1ZkFZv23"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00001.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25LZZQJGGZRPLKTRNRNOTAFQJIPS7WRP"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DC7V5YCLCPB36J2KY6WLZCABFLBRB665"}],"affected":[{"package":{"name":"zbar","ecosystem":"PyPI","purl":"pkg:pypi/zbar"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.23.90"}]}],"versions":["0.10"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-mhp6-jvpx-2p4m/GHSA-mhp6-jvpx-2p4m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}