CVE-2026-102296 ZoneMinder 静态缓冲区溢出漏洞
影响可导致捕获进程崩溃或内存破坏
ZoneMinder 1.38.4 之前版本在 RemoteCameraHttp::GetResponse() 中存在静态缓冲区溢出漏洞。恶意 HTTP 摄像头或中间人可通过发送超大响应头(状态消息、Connection、Content-Type、multipart 边界等)溢出固定大小缓冲区,破坏解析器状态。
影响范围
ZoneMinder 1.38.4 之前的版本。
漏洞详情
漏洞类型为静态缓冲区溢出(CWE-121/120)。成因是解析 HTTP 响应头时未对长度做边界检查,直接写入固定大小栈/静态缓冲区。攻击者通过构造超长状态行、Connection 头、Content-Type 或 multipart boundary 触发溢出,可导致进程崩溃或内存破坏。
利用条件与风险
利用前提是攻击者控制摄像头 HTTP 响应或能中间人拦截流量;实战中可造成拒绝服务,内存破坏是否可进一步利用代码执行暂无公开信息。
修复建议
升级至 ZoneMinder 1.38.4 或更高版本;临时缓解可限制摄像头网络访问、使用可信网络或 TLS 校验,暂无其他公开缓解信息。
ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers can send crafted HTTP responses with oversized status messages, Connection headers, Content-Type values, or multipart boundaries to corrupt parser state and crash the capture process or corrupt memory.