Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Christian Hartlage

#36664of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2020-20626
7.5
2020-02-24
Libzint · Zint · CVE-2020-9385
**Name of the Vulnerable Software and Affected Versions** Zint version 2.7.1 **Description** A NULL Pointer Dereference issue exists in libzint because multiple + characters are mishandled in the `add on` function in upcean.c, when called from `eanx` in upcean.c during EAN barcode generation. **Recommendations** For Zint version 2.7.1, consider disabling the `add on` function in upcean.c as a temporary workaround until a patch is available. Restrict access to the `eanx` function in upcean.c to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.