CVE-2013-0232
Publication date 20 March 2013
Last updated 24 July 2024
Ubuntu priority
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.
Status
Package | Ubuntu Release | Status |
---|---|---|
zoneminder | 18.04 LTS bionic | Not in release |
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |