CVE-2008-6756: Low severity zoneminder vulnerability
Published Apr 27, 2009
·Updated
ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.
Affected Software
2 affected components
ZoneMinder Zoneminder=1.23.3
Gentoo Linux
Event History
Apr 27, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
10:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6756?
CVE-2008-6756 is classified as a medium severity vulnerability due to the exposure of sensitive database information.
2
How do I fix CVE-2008-6756?
To fix CVE-2008-6756, you should change the permissions of /etc/zm.conf to restrict access, such as setting it to 0600.
3
Which software is affected by CVE-2008-6756?
CVE-2008-6756 specifically affects ZoneMinder version 1.23.3 on Gentoo Linux.
4
What type of information can be accessed through CVE-2008-6756?
CVE-2008-6756 allows local users to read the database username and password stored in /etc/zm.conf.
5
Can CVE-2008-6756 be exploited remotely?
CVE-2008-6756 cannot be exploited remotely as it requires local access to the system.