oss-sec mailing list archives
Re: Two more ZoneMinder that need CVE
From: Kurt Seifried <kseifried () redhat com>
Date: Thu, 21 Feb 2013 13:28:16 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 02/21/2013 01:03 PM, Christey, Steven M. wrote:
Actually, CVE covers default accounts and passwords, although known passwords from 1999 and earlier are not covered. While this is arguably "configuration," in 2013, products are expected to have other mechanisms of securing themselves out of the box, such as forcing a credentials change during installation, plus there is usually a race condition between when the product is installed and when the administrator changes the credentials. - Steve
So then as I said in: http://seclists.org/oss-sec/2013/q1/155
1) The default account/password is well documented. The services forces you to change the password when first run and will refuse to run until you do change the password. Generally not considered a vuln.
2) The default account/password is well documented. The services does not force you to change the password when first run. Generally not considered a vuln as it falls into the "don't do stupid things" class of issues.
#2 needs a CVE?
3) The default account/password is not well documented or not documented at all but can be changed. Generally this would be considered a vulnerability.
4) The default account/password is not well documented or not documented at all and can NOT be changed. Generally this would be considered a vulnerability.
- -- Kurt Seifried Red Hat Security Response Team (SRT) PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.13 (GNU/Linux) iQIcBAEBAgAGBQJRJoNgAAoJEBYNRVNeJnmTHGAQAIzzGsK/XPbuwqU0mNZz8eAi DJIGnNB8mhstKkB0y1P7zGb6e7UNcYdT01E34lU3gS9IBTZ3aBnHk7T8JC9TfbAa +nM/S1lpRb8O0LSSDNXFQQtSesEk4fHiz2A/AAhcRDcrRX8bG62mcRWhJW398NTM ZlnI9NNAv7MORrzxN1ZmW/oK1hbglNobjGWVlAQCGtKIVaYt89HVne9WP9Z4ab5D jHHLa9s4Y6EcaCcIjnY4/KrYCOFtjGUe875QhV70T4it9OjyYgmNLHztvbNA0Y5A EWxJVd9tPIoIDw6Acmu0fVpHw59AocS4t6b/se2/FXskt1D17nJ2xhnbVIVnhzdV 66GdK6huYMOiyOjolT2SyrokI0nkHmV56xJ+6OAdjPEEjKX1tqvLIy6kaTGcA7pF /AHGpXZDPsSlxV0fBJ6p9M2RYB9anNhWCsMnG/wJx4sm0j8CM5RdPvcASz38JAsE HrwCn0EDhNhj1umb1hCYZrJ5fb4+z5rmBT6MRE0znj9nHsyGgMMDvaNOw2mWCwC5 k/TlTKQZxsl7JHK2HbWaXA/dJH780unp5sE3N/aUYE95KHvMVXlGFQ9aFyNhVMRM Efl9fd0aLnZR9sI21zfKQv0SUWkGg7C5wT2fxN6IiN47BbnbGAE/FDPf+md7geCH PmqUsV7/4j5avi4iF7/s =qj3J -----END PGP SIGNATURE-----
Current thread:
- Two more ZoneMinder that need CVE security curmudgeon (Feb 21)
- Re: Two more ZoneMinder that need CVE Kurt Seifried (Feb 21)
- RE: Two more ZoneMinder that need CVE Christey, Steven M. (Feb 21)
- Re: Two more ZoneMinder that need CVE Kurt Seifried (Feb 21)
- RE: Two more ZoneMinder that need CVE Christey, Steven M. (Feb 21)
- Re: Two more ZoneMinder that need CVE Kurt Seifried (Feb 21)