Description
A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/delete Monitors, Users, etc.).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-16890 | A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/delete Monitors, Users, etc.). |
References
| Link | Providers |
|---|---|
| https://github.com/ZoneMinder/zoneminder/issues/2476 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T00:31:48.945Z
Reserved: 2019-02-04T00:00:00.000Z
Link: CVE-2019-7347
No data.
Status : Modified
Published: 2019-02-04T19:29:01.337
Modified: 2024-11-21T04:48:04.140
Link: CVE-2019-7347
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD