Re: [Zope] Hotfix for security vulnerability

Laurence Rowe <[email protected]>
Newsgroups gmane.comp.web.zope.devel,gmane.comp.web.zope.general
Message-ID <CAOycyLSMuz56w0YO2=w2BL0nw8Mzt0RXP2Jg5gwJLPs399DSXQ@mail.gmail.com>
On 24 October 2011 22:54, Tres Seaver <[email protected]> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On behalf of the Zope security response team, I would like to announce
> the availability of a hotfix for a vulnerability inadvertently
> published earlier today.
>
> 'Products.Zope_Hotfix_20111024' README
> ======================================
>
> Overview
> - --------
>
> This hotfix addresses a serious vulnerability in the Zope2
> application server.  Affected versions of Zope2 include:
>
> - - 2.12.x <= 2.12.20
>
> - - 2.13.x <= 2.13.6
>
> Older releases (2.11.x, 2.10.x, etc.) are not vulnerable.

Can you confirm whether or not Zope 2.13.6 through 2.13.10 are affected?

Laurence
_______________________________________________
Zope-Dev maillist  -  [email protected]
https://mail.zope.org/mailman/listinfo/zope-dev
**  No cross posts or HTML encoding!  **
(Related lists - 
 https://mail.zope.org/mailman/listinfo/zope-announce
 https://mail.zope.org/mailman/listinfo/zope )
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.