FixVibe
Covered by FixVibehigh

Bayyana Bayanin Kanfigareshan Kanfigareshan ZoneMinder Apache (CVE-2016-10140)

Siffofin ZoneMinder 1.29 da 1.30 sun shafe su ta hanyar kuskuren tsarin sabar Apache HTTP. Wannan aibi yana ba da damar nesa, maharan da ba a tantance su ba don bincika tushen adireshin gidan yanar gizon, mai yuwuwar haifar da bayyana mahimman bayanai da keɓancewar tantancewa.

CVE-2016-10140CWE-200

Tasiri

Mai kai hari mai nisa, wanda ba a tantance shi ba zai iya bincika kundayen adireshi a cikin tushen gidan yanar gizo na shigarwar ZoneMinder [S1]. Wannan fallasa yana ba da damar bayyana bayanan tsarin da ke da mahimmanci kuma yana iya haifar da cikakkiyar wucewa ta tabbatarwa, yana ba da damar shiga mara izini ga tsarin sarrafa aikace-aikacen [S1].

Tushen Dalili

Rashin lahani yana haifar da ƙayyadaddun ƙayyadaddun ƙayyadaddun ƙa'idodin HTTP Server na Apache wanda aka haɗe tare da nau'ikan ZoneMinder 1.29 da 1.30 [S1]. Tsarin ya kasa taƙaita firikwensin directory, wanda ke haifar da sabar gidan yanar gizo tana ba da jerin adireshi ga masu amfani mara inganci [S1].

Gyarawa

Don magance wannan batu, masu gudanarwa yakamata su sabunta ZoneMinder zuwa sigar da ta haɗa da daidaitawar sabar gidan yanar gizo [S1]. Idan haɓakawa nan da nan ba zai yiwu ba, fayilolin sanyi na Apache da ke da alaƙa da shigarwar ZoneMinder yakamata a taurace su da hannu don kashe firikwensin directory da aiwatar da tsauraran matakan samun dama akan tushen gidan yanar gizon [S1].

Binciken Ganowa

Saukewa: ZXCVFIXVIBESEG10 Bincike cikin wannan raunin yana nuna cewa ganowa ya ƙunshi gano wuraren ZoneMinder da ƙoƙarin samun damar tushen gidan yanar gizon ko sanannun kundin adireshi ba tare da tantancewa ba [S1]. Halin da ke da rauni yawanci ana nuna shi ta kasancewar daidaitattun tsarin jeri na adireshi, kamar "Index of /" string, a cikin jikin amsawar HTTP lokacin da babu ingantaccen zaman da ya kasance [S1].