Note:
This project will be discontinued after December 13, 2021. [more]
2019-01-28
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.
Products | Zoneminder |
Type | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) |
First patch | - None (likely due to unavailable code) |
Links |
• https://github.com/ZoneMinder/zoneminder/pull/2482
• https://github.com/ZoneMinder/zoneminder/issues/2478 |