CVE-2019-7347

Name
CVE-2019-7347
Description
A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/delete Monitors, Users, etc.).
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/ZoneMinder/zoneminder/issues/2476

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* zoneminder >= None <= 1.32.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
zoneminder edge-community 1.36.7-r0 Kaarle Ritvanen <kaarle.ritvanen@datakunkku.fi> fixed
zoneminder edge-community 1.30.2-r3 None possibly vulnerable
zoneminder edge-community 1.30.2-r0 None possibly vulnerable
zoneminder 3.22-community 1.36.7-r0 None fixed
zoneminder 3.22-community 1.30.2-r3 None possibly vulnerable
zoneminder 3.22-community 1.30.2-r0 None possibly vulnerable
zoneminder 3.21-community 1.36.7-r0 None fixed
zoneminder 3.20-community 1.36.7-r0 None fixed
zoneminder 3.19-community 1.36.7-r0 None fixed
zoneminder 3.18-community 1.36.7-r0 None fixed
zoneminder 3.17-community 1.36.7-r0 None fixed