Debian Patches

Status for zbar/0.23.93-10

Patch Description Author Forwarded Bugs Origin Last update
0001-Properly-set-perl-script-shebang.patch Properly set perl script shebang Gürkan Myczko <gurkan@phys.ethz.ch> no 2019-07-25
0002-configure.ac-Do-not-use-hardcoded-pkg-config-command.patch configure.ac: Do not use hardcoded pkg-config command
Use overridable $PKG_CONFIG instead.

Also fixes some M4 grammar errors in configure.ac.
Boyuan Yang <byang@debian.org> no 2024-01-09
0003-configure.ac-Use-old-way-to-detect-Qt5.patch configure.ac: Use old way to detect Qt5 Boyuan Yang <byang@debian.org> yes upstream 2024-01-10
0004-qrdectxt-Budget-for-Structured-Append-separators-CVE.patch qrdectxt: Budget for Structured-Append separators (CVE-2026-95516)
qr_code_data_list_extract_text() sizes the output buffer sa_text as
sa_ctext + 1, where sa_ctext is an upper bound on the decoded payload
of the segments of a Structured-Append group that are present in the
image (plus two bytes for an FNC1 Application Indicator). When a
segment of the group is missing, Step 2 writes a '\0' separator in
front of the next present segment, and these separators are not
included in sa_ctext. A group with at least one such gap therefore
writes past the end of the heap buffer, at the separator itself or at
the final terminator. This is reachable from image content through
the public zbar_scan_image() API.

The separators also let sa_ntext grow past sa_ctext. Step 2 computes
the remaining space as sa_ctext - sa_ntext on size_t, so from that
point on the value wraps around and the checks no longer limit the
numeric and alphanumeric copies or the iconv() output space. With
several gaps the overflow is therefore not limited to a single byte.

Fix this by adding sa_size to sa_ctext before anything is allocated.
A separator is only written in front of a present segment that follows
a run of missing ones, so a group has fewer than sa_size of them (at
most 8, since sa_size <= 16), and sa_ntext can no longer exceed
sa_ctext. Both allocations become sa_ctext + sa_size + 1, which is
the sizing suggested by the reporter and reviewed by Red Hat. Doing
it through sa_ctext rather than only in the malloc() calls also keeps
the remaining-space computations in Step 2 from wrapping around.

The payload part of the estimate stays an upper bound: numeric and
alphanumeric data are counted exactly, byte and kanji data at 4 bytes
per input byte, and every character set reachable here (ISO 8859-x,
CP437, Shift_JIS, Big5, UTF-8) produces at most 3 bytes of UTF-8 per
input byte. bytebuf_text only holds raw byte/kanji input (at most
sa_ctext / 4 bytes) and was not affected; it grows by sa_size bytes as
a side effect, which is harmless. The final realloc() still trims
sa_text to the length actually used.

Reported by Calif.io, in collaboration with Anthropic
(reference ANT-2026-KY0E5WN8).
Boyuan Yang <byang@debian.org> no 2026-09-24

All known versions for source package 'zbar'

Links