Files
zoneminder/scripts/ZoneMinder
Isaac Connor 279e467b95 fix: run the event video encoder without a shell
Event::GenerateVideo built an ffmpeg command line as a string and ran it
through qx(), and two of the values in it are event fields an operator with
Events=Edit can set through the API. DefaultVideo was interpolated with no
quoting at all. The name behind the output filename only has its whitespace
replaced, so a single quote in it closed the quoting that was there. Either one
gave arbitrary command execution as the account the daemons run as.

Both confirmed against the module before the change, driving GenerateVideo
directly:

  DefaultVideo = "x.mp4; touch <marker>; echo"     -> marker created
  Name         = "evt';touch${IFS}<marker>;echo'"  -> marker created

The second needs ${IFS} rather than spaces because the name has whitespace
substituted before it is used, which is the whole of the sanitising that was
being relied on.

The command is now a list passed to exec, so there is no shell to escape from
whatever those fields hold; ffmpeg's own output still lands in the event's
ffmpeg.log. The two configured option strings are admin-set and hold several
options each, so they are split on whitespace to become separate arguments;
shell quoting inside them is no longer honoured.

After the change both payloads run ffmpeg with the injection as a literal
argument and create no marker.

See GHSA-pfph-4j9j-7cv7.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WBHBB95RBX7D9p8ge2WDZb
(cherry picked from commit 5fc491728c679bc7a8ff4b51183983e7fe184200)
2026-09-24 19:44:16 -04:00
..