Package: zoneminder
Severity: normal
Tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) id was
published for zoneminder.

CVE-2008-6755[0]:
| ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to
| the apache user account, and sets the permissions to 0600, which makes
| it easier for remote attackers to modify this file by accessing it
| through a (1) PHP or (2) CGI script.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6755
    http://security-tracker.debian.net/tracker/CVE-2008-6755



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to