Release date:
Updated on: 2013-02-02
Affected Systems:
ZoneMinder 1.24.0-1.25.0
Description:
--------------------------------------------------------------------------------
ZoneMinder is a single or multiple camera video security application.
ZoneMinder versions 1.24.0 to 1.25.0 do not correctly verify user input. Multiple Arbitrary Command Execution Vulnerabilities exist in implementation. Attackers can exploit these vulnerabilities to execute arbitrary commands in the context of the affected application.
<* Source: vendor
Link: http://www.30soc.com/News/detail_7203.aspx
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ZoneMinder
----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.zoneminder.com/