CVE-2019-7347: Race Condition
Published Feb 4, 2019
·Updated
A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/delete Monitors, Users, etc.).
Affected Software
1 affected component
ZoneMinder Zoneminder<=1.32.3
Event History
Feb 4, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-7347.
2
What is the severity level of CVE-2019-7347?
The severity level of CVE-2019-7347 is high, with a severity value of 7.5.
3
Which software versions does CVE-2019-7347 affect?
CVE-2019-7347 affects ZoneMinder versions up to and including 1.32.3.
4
What is the CWE ID of CVE-2019-7347?
The CWE ID of CVE-2019-7347 is CWE-362 and CWE-367.
5
Is there a fix available for CVE-2019-7347?
Yes, a fix is available for CVE-2019-7347. It is recommended to update to a version of ZoneMinder that is not affected by this vulnerability.