Impact
ZoneMinder installations prior to 1.38.4 contain a static buffer overflow in the RemoteCameraHttp::GetResponse() function. The vulnerability arises from fixed‑size buffers that can be overflowed by oversized HTTP response headers such as status messages, Connection, Content‑Type, or multipart boundaries. An attacker who can cause a camera to send such headers may corrupt the parser state, resulting in application crashes or corrupt memory.
Affected Systems
All ZoneMinder deployments running in a version older than 1.38.4 are affected. The flaw exists in the core HTTP camera handling module and is triggered for any camera whose response headers are parsed by the server.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability. EPSS data is not available and the flaw is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is remote network access to the camera’s HTTP interface, either by controlling the camera or by intercepting traffic. Triggering the overflow can lead to an application crash or memory corruption; no further legitimate exploitation is documented in the official description.
OpenCVE Enrichment