[Security advisory] Zope 2.7 + 2.8

Andreas Jung <[email protected]>
Newsgroups gmane.comp.web.zope.announce,gmane.comp.web.zope.general,gmane.comp.web.zope.plone.user
Message-ID <599303B1BA0A37E79D420A04@[192.168.0.102]>
Synopsis:

    Due to an error in the cAccessControl module of Zope it is possible to
    bring down a complete Zope site as documented in

     http://mail.zope.org/pipermail/zope-dev/2004-December/024087.html

    This exploit causes a segmentation fault of the Python interpreter.
    Vulnerable for this exploit are at least all Zope installations
    that allow untrusted users to edit ZPTs (possibly DTML as well) either
    through the ZMI or through the file system.


Affected versions:

     Zope 2.7.X, Zope 2.8.X


Recommended solution:

    Turn off cAccessControl and enable the Python AccessControl 
implementation
    in etc/zope.conf (this line is commented in the default configuration):

      security-policy-implemenation python


A fixed implementation of cAccessControl will be included in the upcoming
Zope 2.7.4 beta 2 release.


----
Andreas Jung
Zope 2 Release Manager

_______________________________________________
Zope-Announce maillist  -  [email protected]
http://mail.zope.org/mailman/listinfo/zope-announce

  Zope-Announce for Announcements only - no discussions

(Related lists - 
 Users: http://mail.zope.org/mailman/listinfo/zope
 Developers: http://mail.zope.org/mailman/listinfo/zope-dev )
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.