CVE-2026-102296
HIGH
8,3
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: high
Description
AI Translation Available
ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers can send crafted HTTP responses with oversized status messages, Connection headers, Content-Type values, or multipart boundaries to corrupt parser state and crash the capture process or corrupt memory.
120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Modify Memory
Execute Unauthorized Code Or Commands
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Applicable Platforms
Languages:
Memory-Unsafe, C, C++, Assembly
https://github.com/ZoneMinder/zoneminder
https://github.com/ZoneMinder/zoneminder/blob/1.38.3/src/zm_remote_camera_http.…
https://github.com/ZoneMinder/zoneminder/commit/2596e5fb64c0348e615577b0ab08dc3…
https://github.com/ZoneMinder/zoneminder/commit/813bf6f1a3ffc92c163352f2480477b…
https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.4
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-93j4-rcp9-9jx6
https://www.vulncheck.com/advisories/zoneminder-before-1.38.4-buffer-overflow-v…