CVE-2017-5595
published 2017-02-06CVE-2017-5595: A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to…
PriorityP424medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.43%
35.0th percentile
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zoneminder | < zoneminder 1.30.4+dfsg-1 (bookworm) | zoneminder 1.30.4+dfsg-1 (bookworm) |
| zoneminder | zoneminder | <= 1.30.0 | — |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
| zoneminder | zoneminder | >= 0 < 1.30.4+dfsg-1 | 1.30.4+dfsg-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-88gp-83c5-44hg: A file disclosure and inclusion vulnerability exists in web/views/file
ghsa_unreviewed·2022-05-17
CVE-2017-5595 [MEDIUM] CWE-200 GHSA-88gp-83c5-44hg: A file disclosure and inclusion vulnerability exists in web/views/file
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.
OSV
CVE-2017-5595: A file disclosure and inclusion vulnerability exists in web/views/file
osv·2017-02-06·CVSS 5.5
CVE-2017-5595 [MEDIUM] CVE-2017-5595: A file disclosure and inclusion vulnerability exists in web/views/file
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.
Debian
CVE-2017-5595: zoneminder - A file disclosure and inclusion vulnerability exists in web/views/file.php in Zo...
vendor_debian·2017·CVSS 5.5
CVE-2017-5595 [MEDIUM] CVE-2017-5595: zoneminder - A file disclosure and inclusion vulnerability exists in web/views/file.php in Zo...
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.
Scope: local
bookworm: resolved (fixed in 1.30.4+dfsg-1)
bullseye: resolved (fixed in 1.30.4+dfsg-1)
forky: resolved (fixed in 1.30.4+dfsg-1)
sid: resolved (fixed in 1.30.4+dfsg-1)
trixie: resolved (fixed in 1.30.4+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input
bugzilla·2017-02-06·CVSS 5.5
CVE-2017-5595 [MEDIUM] CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input
CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input
File disclosure and inclusion vulnerability exists in ZoneMinder due to unfiltered user-input being passed to readfile() in views/file.php which allows an authenticated attacker to read local system files (e.g. /etc/passwd) in the context of the web server user (www-data).
References:
http://seclists.org/bugtraq/2017/Feb/6
Upstream patch:
https://github.com/ZoneMinder/ZoneMinder/commit/8b19fca9927cdec07cc9dd09bdcf2496a5ae69b3
Discussion:
Created zoneminder tracking bugs for this issue:
Affects: fedora-all [bug 1419509]
---
Strange, the link above does not contain all three commits which make up this fix.
Please use this link instead:
https://patch-diff.githubusercontent.com/raw/ZoneMinder/ZoneMinder/pull/1758
Bugzilla
CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input [fedora-all]
bugzilla·2017-02-06·CVSS 5.5
CVE-2017-5595 [MEDIUM] CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input [fedora-all]
CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
http://seclists.org/bugtraq/2017/Feb/6http://seclists.org/fulldisclosure/2017/Feb/11http://www.securityfocus.com/bid/96125https://github.com/ZoneMinder/ZoneMinder/commit/8b19fca9927cdec07cc9dd09bdcf2496a5ae69b3http://seclists.org/bugtraq/2017/Feb/6http://seclists.org/fulldisclosure/2017/Feb/11http://www.securityfocus.com/bid/96125https://github.com/ZoneMinder/ZoneMinder/commit/8b19fca9927cdec07cc9dd09bdcf2496a5ae69b3
2017-02-06
Published