LWN.net Logo

zoneminder: multiple vulnerabilities

Package(s):zoneminder CVE #(s):CVE-2013-0232 CVE-2013-0332
Created:March 15, 2013 Updated:April 3, 2013
Description:

From the Debian advisory:

Multiple vulnerabilities were discovered in zoneminder, a Linux video camera security and surveillance solution. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2013-0232: Brendan Coles discovered that zoneminder is prone to an arbitrary command execution vulnerability. Remote (authenticated) attackers could execute arbitrary commands as the web server user.

CVE-2013-0332: zoneminder is prone to a local file inclusion vulnerability. Remote attackers could examine files on the system running zoneminder.

Alerts:
Debian DSA-2640-1 2013-03-14
Mageia MGASA-2013-0104 2013-04-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds