CVE-2016-10140
published 2017-01-13CVE-2016-10140: Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which…
PriorityP354high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
6.74%
93.2th percentile
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zoneminder | < zoneminder 1.30.4+dfsg-1 (bookworm) | zoneminder 1.30.4+dfsg-1 (bookworm) |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated HTTP requests to the /events URI on ZoneMinder servers, which may indicate directory browsing or CCTV image enumeration by an attacker. ↗
- →Check Apache HTTP Server config file /etc/httpd/conf.d/zoneminder.conf for absence of 'Options -Indexes', which indicates the server is vulnerable to directory listing. Non-vulnerable configs contain: Options -Indexes +MultiViews +FollowSymLinks ↗
- →Flag ZoneMinder installations running v1.29 or v1.30 (prior to 1.30.4) as vulnerable to unauthenticated directory traversal and information disclosure via misconfigured Apache HTTP Server bundled config. ↗
- ·The vulnerability is in the bundled Apache HTTP Server configuration for ZoneMinder v1.29 and v1.30 (fixed in v1.30.4). Fedora 24 and 25 with zoneminder-1.28.1 are NOT affected as their configs already include 'Options -Indexes'. ↗
- ·Debian-based systems are resolved at package version 1.30.4+dfsg-1 across all active releases (bookworm, bullseye, sid, trixie, forky). ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-10140: zoneminder - Information disclosure and authentication bypass vulnerability exists in the Apa...
vendor_debian·2016·CVSS 7.5
CVE-2016-10140 [HIGH] CVE-2016-10140: zoneminder - Information disclosure and authentication bypass vulnerability exists in the Apa...
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.
Scope: local
bookworm: resolved (fixed in 1.30.4+dfsg-1)
bullseye: resolved (fixed in 1.30.4+dfsg-1)
forky: resolved (fixed in 1.30.4+dfsg-1)
sid: resolved (fixed in 1.30.4+dfsg-1)
trixie: resolved (fixed in 1.30.4+dfsg-1)
GHSA
GHSA-qgrq-7wwj-vr5c: Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1
ghsa_unreviewed·2022-05-17
CVE-2016-10140 [HIGH] CWE-200 GHSA-qgrq-7wwj-vr5c: Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.
OSV
CVE-2016-10140: Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1
osv·2017-01-13·CVSS 7.5
CVE-2016-10140 [HIGH] CVE-2016-10140: Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10140 zoneminder: Information disclosure and authentication bypass [fedora-all]
bugzilla·2017-01-17·CVSS 7.5
CVE-2016-10140 [HIGH] CVE-2016-10140 zoneminder: Information disclosure and authentication bypass [fedora-all]
CVE-2016-10140 zoneminder: Information disclosure and authentication bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2016-10140 zoneminder: Information disclosure and authentication bypass
bugzilla·2017-01-17·CVSS 7.5
CVE-2016-10140 [HIGH] CVE-2016-10140 zoneminder: Information disclosure and authentication bypass
CVE-2016-10140 zoneminder: Information disclosure and authentication bypass
Information disclosure and authentication bypass vulnerability exists
in the Apache HTTP Server configuration bundled with ZoneMinder
v1.30.0, which allows a remote unauthenticated attacker to browse all
directories in the web root, e.g., a remote unauthenticated attacker
can view all CCTV images on the server.
Upstream bug:
https://github.com/ZoneMinder/ZoneMinder/pull/1697
Discussion:
Created zoneminder tracking bugs for this issue:
Affects: fedora-all [bug 1413909]
---
Fedora 26/rawhide not affected. zoneminder has been retired from master because it is moving to RPM Fusion.
Fedora 25 not affected. zoneminder-1.28.1-6.fc25 has:
./etc/httpd/conf.d/zoneminder.conf: Options -Indexes +MultiViews +FollowSymL
http://seclists.org/bugtraq/2017/Feb/6http://seclists.org/fulldisclosure/2017/Feb/11http://www.securityfocus.com/bid/96849https://github.com/ZoneMinder/ZoneMinder/commit/71898df7565ed2a51dfe76a1cf30ddb81fc888bahttps://github.com/ZoneMinder/ZoneMinder/pull/1697http://seclists.org/bugtraq/2017/Feb/6http://seclists.org/fulldisclosure/2017/Feb/11http://www.securityfocus.com/bid/96849https://github.com/ZoneMinder/ZoneMinder/commit/71898df7565ed2a51dfe76a1cf30ddb81fc888bahttps://github.com/ZoneMinder/ZoneMinder/pull/1697
2017-01-13
Published