UBUNTU-CVE-2022-29806
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-29806
UBUNTU-CVE-2022-29806
Summary:
Details: ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
References: https://ubuntu.com/security/CVE-2022-29806, https://forums.zoneminder.com/viewtopic.php?t=31638, https://github.com/ZoneMinder/zoneminder/commit/9fee64b62fbdff5bf5ece1d617f1f53c7b1967cb, https://github.com/ZoneMinder/zoneminder/releases/tag/1.36.13, https://krastanoel.com/cve/2022-29806, https://ubuntu.com/security/notices/USN-5889-1, https://www.cve.org/CVERecord?id=CVE-2022-29806
Affected packages
Package
Name: zoneminder
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu2+esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
