FixVibe
Covered by FixVibehigh

I-ZoneMinder Apache Configuration Information Disclosure (CVE-2016-10140)

Izinguqulo ze-ZoneMinder 1.29 kanye no-1.30 zithintwa ukungalungiselelwa kahle kwe-Apache HTTP Server. Leli phutha livumela abahlaseli abakude, abangagunyaziwe ukuthi baphequlule uhla lwemibhalo lwempande yewebhu, okungase kuholele ekudalulweni kolwazi olubucayi kanye nokudlula kokuqinisekisa.

CVE-2016-10140CWE-200

Umthelela

Umhlaseli okude, ongagunyaziwe angaphequlula izinkomba ngaphakathi kwempande yewebhu yokufakwa kwe-ZoneMinder [S1]. Lokhu kuvezwa kuvumela ukudalulwa kolwazi lwesistimu olubucayi futhi kungaholela ekudluleleni kokuqinisekisa okuphelele, kunikeze ukufinyelela okungagunyaziwe kusixhumi esibonakalayo sokuphatha sohlelo lokusebenza [S1].

Imbangela

Ukuba sengozini kubangelwa ukulungiselelwa kwe-Apache HTTP Server enephutha ehlanganiswe nezinguqulo ze-ZoneMinder 1.29 kanye no-1.30 [S1]. Ukulungiselelwa kwehluleka ukukhawulela ukukhonjwa kohla lwemibhalo, okuholela ekunikezeni uhlu lwemibhalo kuseva yewebhu kubasebenzisi abangagunyaziwe [S1].

Ukulungiswa

Ukuze kubhekwane nale nkinga, abalawuli kufanele babuyekeze i-ZoneMinder ibe inguqulo ehlanganisa ukulungiselelwa okulungisiwe kweseva yewebhu [S1]. Uma ukuthuthukiswa okusheshayo kungenzeki, amafayela okulungiselela we-Apache ahlotshaniswa nokufakwa kwe-ZoneMinder kufanele enziwe lukhuni ukuze kukhubazwe ukukhonjwa kohlu lwemibhalo futhi kuphoqelelwe izilawuli zokufinyelela eziqinile kumsuka wewebhu [S1].

Ucwaningo Lokuthola

Ucwaningo mayelana nalokhu kuba sengcupheni lubonisa ukuthi ukutholwa kuhilela ukuhlonza izimo ze-ZoneMinder kanye nokuzama ukufinyelela impande yewebhu noma izinkombandlela ezingaphansi ezaziwayo ngaphandle kokuqinisekisa [S1]. Isimo esisengozini ngokuvamile siboniswa ukuba khona kwamaphethini ohlu lwemibhalo ajwayelekile, njengeyunithi yezinhlamvu ethi "Inkomba ye-/", emzimbeni wokuphendula we-HTTP uma ingekho iseshini evumelekile [S1].