ZoneMinder Remote Multiple Arbitrary Command Execution Vulnerabilities
BID:57544
Info
ZoneMinder Remote Multiple Arbitrary Command Execution Vulnerabilities
| Bugtraq ID: | 57544 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0232 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2013 12:00AM |
| Updated: | Mar 26 2013 10:46AM |
| Credit: | Brendan Coles |
| Vulnerable: |
Triornis ZoneMinder 1.24.4 Triornis ZoneMinder 1.24.3 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
ZoneMinder Remote Multiple Arbitrary Command Execution Vulnerabilities
ZoneMinder is prone to multiple arbitrary command-execution vulnerabilities because it fails to properly validate user-supplied input.
An attacker can exploit these issues to execute arbitrary commands within the context of the vulnerable application.
ZoneMinder 1.24.0 through 1.25.0 are vulnerable.
ZoneMinder is prone to multiple arbitrary command-execution vulnerabilities because it fails to properly validate user-supplied input.
An attacker can exploit these issues to execute arbitrary commands within the context of the vulnerable application.
ZoneMinder 1.24.0 through 1.25.0 are vulnerable.
Exploit / POC
ZoneMinder Remote Multiple Arbitrary Command Execution Vulnerabilities
Attackers can use a browser to exploit these issues.
The following exploits is available:
Attackers can use a browser to exploit these issues.
The following exploits is available:
Solution / Fix
ZoneMinder Remote Multiple Arbitrary Command Execution Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
ZoneMinder Remote Multiple Arbitrary Command Execution Vulnerabilities
References:
References:
- ZoneMinder Home Page (Triornis Ltd.)