Candidate: CVE-2018-1000832 PublicDate: 2018-12-20 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000832 https://0dd.zone/2018/10/28/zoneminder-Object-Injection/ https://github.com/ZoneMinder/zoneminder/issues/2271 Description: ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_zoneminder: upstream_zoneminder: released (1.32.3-2) precise/esm_zoneminder: DNE trusty_zoneminder: ignored (reached end-of-life) trusty/esm_zoneminder: DNE (trusty was needs-triage) xenial_zoneminder: ignored (end of standard support, was needed) bionic_zoneminder: DNE cosmic_zoneminder: ignored (reached end-of-life) disco_zoneminder: not-affected (1.32.3-2) eoan_zoneminder: not-affected (1.32.3-2build1) focal_zoneminder: not-affected (1.32.3-2build1) groovy_zoneminder: not-affected (1.32.3-2build1) hirsute_zoneminder: not-affected (1.32.3-2build1) impish_zoneminder: not-affected (1.32.3-2build1) jammy_zoneminder: not-affected (1.32.3-2build1) devel_zoneminder: not-affected (1.32.3-2build1)