Fwd: [Zope-dev] Annoucment: CVE-2010-1104, hotfix, Zope 2.12.22 and 2.13.12 releases
Georges Racinet <[email protected]> Wed, 18 Jan 2012 23:46:32 +0100
| Newsgroups | gmane.comp.web.zope.cps.general.french,gmane.comp.web.zope.cps.devel |
|---|---|
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --===============1529103810== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="------------enig923F6F12AB3EB625359D1B76" This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enig923F6F12AB3EB625359D1B76 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Bonsoir =E0 tous, (english version below) Zope a annonc=E9 un correctif =E0 chaud pour une vuln=E9rabilit=E9 de typ= e cross-site-scripting. Apr=E8s v=E9rification sur http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=3D2010-1104 et http://web.nvd.nist.gov/view/vuln/detail?vulnId=3DCVE-2010-1104, il semblerait que Zope 2.9.12 et 2.10.12, les versions les plus courantes sur lesquelles tourne CPS 3.5 ne soit pas affect=E9es. Ce sont notamment les versions qu'on retrouve dans les paquets Debian de apt.cps-cms.org. ---- A hotfix has been announced for a cross-site-scripting vulnerability on the zope mailing-list. After checking on http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=3D2010-1104 and http://web.nvd.nist.gov/view/vuln/detail?vulnId=3DCVE-2010-1104, it seems that Zope 2.9.12 and 2.10.12, which are the most common versions on which CPS-3.5 are not vulnerable to this issue. These versions are precisely those that have are available as Debian packages on apt.cps-cms.org. -------- Message original -------- Sujet: [Zope-dev] Annoucment: CVE-2010-1104, hotfix, Zope 2.12.22 and 2.13.12 releases Date : Wed, 18 Jan 2012 17:30:30 -0500 De : Tres Seaver <[email protected]> Pour : [email protected], [email protected], Zope Developers <[email protected]>, [email protected] Overview =3D=3D=3D=3D=3D=3D=3D=3D In response to the cross-site scripting vulnerability in Zope2 reported a= s 'CVE 2010-1104'[1], the Zope security response team announces the availablility of a hotfix product (for Zope < 2.12), and new releases for= the Zope 2.12 and 2.13 lines: Hotfix: http://pypi.python.org/pypi/Products.Zope_Hotfix_CVE_2010_1104 Zope 2.12.22: http://pypi.python.org/pypi/Zope2/2.12.22 Zope 2.13.12: http://pypi.python.org/pypi/Zope2/2.13.12 WARNING: Zope < 2.12 is no longer officially supported, and may have other unpatched vulnerabilities. You are encouraged to upgrade to a supported Zope 2. Installing the Hotfix =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D The hotfix has been tested with Zope instances using Zope 2.8.x - 2.11.x.= Users of Zope 2.12.x and 2.13.x should instead update to the latest corresponding minor revision, which already includes this fix. Download the tarball from the PyPI page: http://pypi.python.org/pypi/Products.Zope_Hotfix_CVE_2010_1104 Unpack the tarball and add a 'products' key to the 'etc/zope.conf' of your instance. E.g.:: products /path/to/Products.Zope_Hotfix_CVE_2010_1104/Products and restart. Alternatively, you may copy or symlink the 'Products' directory into the 'Products' subdirectory of your Zope instance. E.g.::= $ cp -r /path/to/Products.Zope_Hotfix_CVE_2010_1104/Products \ /path/to/instance/Products/ Verifying the Installation -------------------------- After restarting the Zope instance, check the 'Control_Panel/Products' folder in the Zope Management Interface, e.g.: http://localhost:8080/Control_Panel/Products/manage_main You should see the 'Zope_Hotfix_CVE_2010_1104' product folder there. [1] http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=3D2010-1104 Tres. _______________________________________________ Zope-Dev maillist - [email protected] https://mail.zope.org/mailman/listinfo/zope-dev ** No cross posts or HTML encoding! ** (Related lists - https://mail.zope.org/mailman/listinfo/zope-announce https://mail.zope.org/mailman/listinfo/zope ) --------------enig923F6F12AB3EB625359D1B76 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iQEcBAEBAgAGBQJPF0vPAAoJEOAffZJiF+Z4wk8IAKVqZAX5j24eV+tYULISCPZ8 cqI0V3Jb3p0rp3umgZCfD7zH8fkwr+PQ3s9GiRo9DhkbL1Jr+jzdmRMwNrk4mbV9 0drRqlT05uACYVbd+OGjtC7wRuUvB2kRsZBlIAwQz1cklrnd+knuqU2VBNhce+YY PLSCzh6ZpxSJNwBvtVFFIRMNlHS/vSL4hxQKcccjii0s4k35WGGu+vAq2ocenslw iO3XD/jGHuiMdVV88yUD4jZ2wsX/QI4l+Nrs5OmDN+eMmng2aMMXQRbFGr5eWAaJ kldoHN8UAQeIZoMwBzHqJpbXKww7shMj4efPnAsRFWXfIpWnP0wYI14o7FwwT3s= =sTtC -----END PGP SIGNATURE----- --------------enig923F6F12AB3EB625359D1B76-- --===============1529103810== Content-Type: text/plain; charset="iso-8859-1" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline _______________________________________________ cps-users-fr Adresse de la liste : [email protected] Gestion de l'abonnement : <http://lists.nuxeo.com/mailman/listinfo/cps-user= s-fr> --===============1529103810==--