oss-sec mailing list archives
CVE request: zoneminder: local file inclusion vulnerability
From: Salvatore Bonaccorso <carnil () debian org>
Date: Tue, 19 Feb 2013 10:47:31 +0100
Hi In zoneminder forum the following announce was done already in 2011: http://www.zoneminder.com/forums/viewtopic.php?f=1&t=17979 where zoneminder is prone to a local file inclusion vulnerability.
From upstream versions prior to 1.24.4 are affected and the issue was
fixed in 1.24.4 and 1.25.0. SVN commits fixing this issue for the 1.24.x versions are r3483 and r3488, and patches: http://www.zoneminder.com/downloads/lfi-patch.txt http://www.zoneminder.com/downloads/lfi-patch2.txt I haven't found a CVE assigned to this already. In case I did not miss something, could you allocate a CVE for this issue? Debian Bug: http://bugs.debian.org/700912 Regards, Salvatore
Current thread:
- CVE request: zoneminder: local file inclusion vulnerability Salvatore Bonaccorso (Feb 19)
- Re: CVE request: zoneminder: local file inclusion vulnerability Kurt Seifried (Feb 20)
- Re: CVE request: zoneminder: local file inclusion vulnerability Salvatore Bonaccorso (Feb 21)
- Re: CVE request: zoneminder: local file inclusion vulnerability Kurt Seifried (Feb 20)