Debian Patches
Status for zbar/0.23.93-10
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| 0001-Properly-set-perl-script-shebang.patch | Properly set perl script shebang | Gürkan Myczko <gurkan@phys.ethz.ch> | no | 2019-07-25 | ||
| 0002-configure.ac-Do-not-use-hardcoded-pkg-config-command.patch | configure.ac: Do not use hardcoded pkg-config command Use overridable $PKG_CONFIG instead. Also fixes some M4 grammar errors in configure.ac. |
Boyuan Yang <byang@debian.org> | no | 2024-01-09 | ||
| 0003-configure.ac-Use-old-way-to-detect-Qt5.patch | configure.ac: Use old way to detect Qt5 | Boyuan Yang <byang@debian.org> | yes | upstream | 2024-01-10 | |
| 0004-qrdectxt-Budget-for-Structured-Append-separators-CVE.patch | qrdectxt: Budget for Structured-Append separators (CVE-2026-95516) qr_code_data_list_extract_text() sizes the output buffer sa_text as sa_ctext + 1, where sa_ctext is an upper bound on the decoded payload of the segments of a Structured-Append group that are present in the image (plus two bytes for an FNC1 Application Indicator). When a segment of the group is missing, Step 2 writes a '\0' separator in front of the next present segment, and these separators are not included in sa_ctext. A group with at least one such gap therefore writes past the end of the heap buffer, at the separator itself or at the final terminator. This is reachable from image content through the public zbar_scan_image() API. The separators also let sa_ntext grow past sa_ctext. Step 2 computes the remaining space as sa_ctext - sa_ntext on size_t, so from that point on the value wraps around and the checks no longer limit the numeric and alphanumeric copies or the iconv() output space. With several gaps the overflow is therefore not limited to a single byte. Fix this by adding sa_size to sa_ctext before anything is allocated. A separator is only written in front of a present segment that follows a run of missing ones, so a group has fewer than sa_size of them (at most 8, since sa_size <= 16), and sa_ntext can no longer exceed sa_ctext. Both allocations become sa_ctext + sa_size + 1, which is the sizing suggested by the reporter and reviewed by Red Hat. Doing it through sa_ctext rather than only in the malloc() calls also keeps the remaining-space computations in Step 2 from wrapping around. The payload part of the estimate stays an upper bound: numeric and alphanumeric data are counted exactly, byte and kanji data at 4 bytes per input byte, and every character set reachable here (ISO 8859-x, CP437, Shift_JIS, Big5, UTF-8) produces at most 3 bytes of UTF-8 per input byte. bytebuf_text only holds raw byte/kanji input (at most sa_ctext / 4 bytes) and was not affected; it grows by sa_size bytes as a side effect, which is harmless. The final realloc() still trims sa_text to the length actually used. Reported by Calif.io, in collaboration with Anthropic (reference ANT-2026-KY0E5WN8). |
Boyuan Yang <byang@debian.org> | no | 2026-09-24 |
All known versions for source package 'zbar'
- 0.23.93-10 (sid, forky)
- 0.23.93-8 (trixie)
- 0.23.92-7+deb12u1 (bookworm-security, bookworm)
