ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zoneminder | Zoneminder | 1.23.3 (including) | 1.23.3 (including) |
Zoneminder | Ubuntu | hardy | * |
Zoneminder | Ubuntu | intrepid | * |
Zoneminder | Ubuntu | jaunty | * |
Zoneminder | Ubuntu | upstream | * |