Description
ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers can send crafted HTTP responses with oversized status messages, Connection headers, Content-Type values, or multipart boundaries to corrupt parser state and crash the capture process or corrupt memory.
Published: 2026-09-28
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Buffer Overflow enabling memory corruption or denial of service
Action: Immediate Patch
AI Analysis

Impact

ZoneMinder installations prior to 1.38.4 contain a static buffer overflow in the RemoteCameraHttp::GetResponse() function. The vulnerability arises from fixed‑size buffers that can be overflowed by oversized HTTP response headers such as status messages, Connection, Content‑Type, or multipart boundaries. An attacker who can cause a camera to send such headers may corrupt the parser state, resulting in application crashes or corrupt memory.

Affected Systems

All ZoneMinder deployments running in a version older than 1.38.4 are affected. The flaw exists in the core HTTP camera handling module and is triggered for any camera whose response headers are parsed by the server.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity vulnerability. EPSS data is not available and the flaw is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is remote network access to the camera’s HTTP interface, either by controlling the camera or by intercepting traffic. Triggering the overflow can lead to an application crash or memory corruption; no further legitimate exploitation is documented in the official description.

Generated by OpenCVE AI on September 28, 2026 at 23:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official ZoneMinder patch v1.38.4 or later to eliminate the fixed‑size buffer vulnerability.
  • If patching cannot be performed immediately, block or filter oversized HTTP response headers at the network or application level to prevent the overflow from reaching the camera handler.
  • If disabling cameras temporarily is acceptable, isolate or quarantine any cameras that may send malicious responses while remediation is underway.

Generated by OpenCVE AI on September 28, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers can send crafted HTTP responses with oversized status messages, Connection headers, Content-Type values, or multipart boundaries to corrupt parser state and crash the capture process or corrupt memory.
Title ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response
First Time appeared Zoneminder
Zoneminder zoneminder
Weaknesses CWE-120
CPEs cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*
Vendors & Products Zoneminder
Zoneminder zoneminder
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Zoneminder Zoneminder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T22:28:08.065Z

Reserved: 2026-09-28T21:24:39.616Z

Link: CVE-2026-102296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T22:17:32.233

Modified: 2026-09-28T22:17:32.233

Link: CVE-2026-102296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T00:15:09Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')