[Ann] Zope Hotfix 2005-10-09

Andreas Jung <[email protected]>
Newsgroups gmane.comp.web.zope.announce
Message-ID <8FE1477C091157333B34DD1C__3536.64271901852$1128876030$gmane$org@suxmac>
Hello,

a security issue with the Docutils package coming with Zope 2.6 or higher 
has been discovered. Sites that expose reStructuredText functionality to
untrusted users (typically portal sites allowing registered users to edit 
content) are possibly affected.

Download location and installation are available from

   http://www.zope.org/Products/Zope/Hotfix_2005-10-09/security_alert

The hotfix is supposed to work with any Zope 2.7 and 2.8 version.
It might work for Zope 2.6 and Python 2.1 but we can not give a guarantee 
since Zope 2.6 is no longer maintained. Plone sites do not seem to be 
affected (there seems to be some additional code on top of Zope's
reST implementation avoiding the failure) however this not a guarantee.
The upcoming Zope 2.8.2 and 2.7.8 releases will also ship with the hotfix.


Andreas Jung

_______________________________________________
Zope-Announce maillist  -  [email protected]
http://mail.zope.org/mailman/listinfo/zope-announce

  Zope-Announce for Announcements only - no discussions

(Related lists - 
 Users: http://mail.zope.org/mailman/listinfo/zope
 Developers: http://mail.zope.org/mailman/listinfo/zope-dev )
signature.asc (application/pgp-signature, 186 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (Darwin)

iD8DBQFDSUeZCJIWIbr9KYwRAvjlAJwKaxjbJyo49gJeOneTkug3oo+nxwCeJkOg
Ri5QCTwvldxURWrpZ05h+Qs=
=rJdk
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.