First published: Mon Apr 27 2009(Updated: )
ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZoneMinder | =1.23.3 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6756 is classified as a medium severity vulnerability due to the exposure of sensitive database information.
To fix CVE-2008-6756, you should change the permissions of /etc/zm.conf to restrict access, such as setting it to 0600.
CVE-2008-6756 specifically affects ZoneMinder version 1.23.3 on Gentoo Linux.
CVE-2008-6756 allows local users to read the database username and password stored in /etc/zm.conf.
CVE-2008-6756 cannot be exploited remotely as it requires local access to the system.