Candidate: CVE-2019-7347 PublicDate: 2019-02-04 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7347 https://github.com/ZoneMinder/zoneminder/issues/2476 Description: A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authenticated user even after deletion from the users table. This allows a nonexistent user to access and modify records (add/delete Monitors, Users, etc.). Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.5 HIGH] Patches_zoneminder: upstream: https://github.com/ZoneMinder/zoneminder/commit/2b90bf15a6d357819b16c56dcf24dec2baf5892d upstream_zoneminder: needs-triage precise/esm_zoneminder: DNE trusty_zoneminder: ignored (reached end-of-life) trusty/esm_zoneminder: DNE (trusty was needs-triage) xenial_zoneminder: ignored (end of standard support, was needed) bionic_zoneminder: DNE cosmic_zoneminder: ignored (reached end-of-life) disco_zoneminder: ignored (reached end-of-life) eoan_zoneminder: ignored (reached end-of-life) focal_zoneminder: needed groovy_zoneminder: ignored (reached end-of-life) hirsute_zoneminder: ignored (reached end-of-life) impish_zoneminder: needed jammy_zoneminder: needed devel_zoneminder: needed