[Git][security-tracker-team/security-tracker][master] Add CVE-2023-41884/zoneminder

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 12 21:24:44 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
386016bb by Salvatore Bonaccorso at 2024-08-12T22:24:08+02:00
Add CVE-2023-41884/zoneminder

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -121,7 +121,11 @@ CVE-2023-7249 (Improper Limitation of a Pathname to a Restricted Directory ('Pat
 CVE-2023-48171 (An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker ...)
 	TODO: check
 CVE-2023-41884 (ZoneMinder is a free, open source Closed-circuit television software a ...)
-	TODO: check
+	- zoneminder <unfixed> (unimportant)
+	NOTE: Only supported for trusted users/behind auth
+	NOTE: https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-2qp3-fwpv-mc96
+	NOTE: https://github.com/ZoneMinder/zoneminder/commit/677f6a31551f128554f7b0110a52fd76453a657a (1.36.34)
+	NOTE: https://github.com/ZoneMinder/zoneminder/commit/a194fe81d34c5eea2ab1dc18dc8df615fca634a6 (1.37.61)
 CVE-2024-7694 (ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the ...)
 	NOT-FOR-US: ThreatSonar Anti-Ransomware
 CVE-2024-7693 (Raiden MAILD Remote Management System from Team Johnlong Software has  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/386016bb5fd5d034f57eda7f1da8b50a9b16ca63

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/386016bb5fd5d034f57eda7f1da8b50a9b16ca63
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240812/1ce73e56/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list