
IMPORTANT - Security Patch for ZM 1.24.x
An issue has been reported which could result in authenticated users being able to examine arbitrary files on your system. This has been fixed in 1.25.0 and I have created a patch to allow the fix to be applied to previous versions.
The patch is available from
here and I urge users to apply the patch as soon as possible. It only patches PHP files so can be applied directly to package installs as well as source builds.
To apply the patch go to the top level of your ZoneMinder source directory and type the following.
You should then see output something like
which will indicate success. If you are patching installed systems rather than source you can run the patch from the installed ZM web directory and change -p0 to -p1.
Please note that the issue that this patch addresses applies to authenticated users on systems with authentication enabled, or for any users on systems which do not require authentication. Not all systems appear to exhibit the problem even in these circumstances, possibly due to different PHP configuration, but I recommend applying the patch on all systems anyway. Please note that the version of 1.24.4 available for download as from today (28/7) has been updated with this patch.