{"id":"UBUNTU-CVE-2017-5595","details":"A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.","modified":"2025-09-08T16:44:07Z","published":"2017-02-06T17:59:00Z","upstream":["CVE-2017-5595"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-5595"},{"type":"REPORT","url":"http://seclists.org/bugtraq/2017/Feb/6"},{"type":"REPORT","url":"http://seclists.org/fulldisclosure/2017/Feb/11"},{"type":"REPORT","url":"https://github.com/ZoneMinder/ZoneMinder/commit/8b19fca9927cdec07cc9dd09bdcf2496a5ae69b3"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2017/02/05/1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2017-5595"}],"affected":[{"package":{"name":"zoneminder","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/zoneminder@1.29.0+dfsg-1ubuntu2+esm1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.28.1-8","1.29.0+dfsg-1","1.29.0+dfsg-1ubuntu1","1.29.0+dfsg-1ubuntu2","1.29.0+dfsg-1ubuntu2+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"zoneminder","binary_version":"1.29.0+dfsg-1ubuntu2+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-5595.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}