Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

Julien Cristau <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc,gmane.comp.web.zope.devel
Message-ID <[email protected]>
On Mon, Nov 26, 2012 at 18:53:58 +0900, Arnaud Fontaine wrote:

> Tres Seaver <[email protected]> writes:
> 
> >> * CVE-2012-5505 (zope.traversing: atat.py)
> >> http://plone.org/products/plone/security/advisories/20121106/21
> >
> > That "fix" is  also disputed: hiding the "default" view  from the '@@'
> > name does not actually improve security  at all.  There is a Launchpad
> > bug where  it is being  debated (#1079225), but  that bug is  still in
> > "Private Security" mode.  The correct fix is to change the code of the
> > multi-adapter to barf if published via a URL.
> 
> Any idea when this patch will be released? Thanks.
> 
Is there any news on that issue?

Cheers,
Julien
signature.asc (application/pgp-signature, 836 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJRBTB7AAoJEDEBgAUJBeQMBMgQALKPo+emO3AJYCN5LQ5+LkS3
UD+POeqkCemlN6ZzrGca+KV+AYsiDLKgyjuZ5LQ2X+Eic5JRMB5gKiSYSBtzqyvk
FDUemsVcFu0PDoSS2Dfx/vZs17/vPT9+ZSMGcMgL09GeQ53YbIOtV3xj1gRFNlPs
+/o8VtPj79UtGoqF/W0rtBclF+/9ld6XtqR6he2hGDwK4VAx+W8RlM227HVDY9Th
3ccyKxI9pwedNs5UwgDHjt05wzWnsnZE1OP6P9Q59BSXTTrVxdvTJpxVH3JtMiI9
qRnzYs0+195/E53M1rL+8IF+GaKM8u2ZjYyUbTG0XBBCufraDJj/x+duLR+vvECR
ytkD27BAbM1VdDd6Lttzmyjsth9i8SXHWJl4oRPUQAYPHnw3FugzPi6Z0RjV8TEj
pCgfaOqlZv9brvMegPewnL/5xHk0ImVzEMv0lo2RKGkaHO5dwFoY1/KQVNgsLTdL
Msx042pzmeUo4SaabnbX11Hyms6m0roYxvLy5cZ0psE+crv+bamAtsQgPv0FnQuD
HVB9EKI3rjcxu78dcJD3K0JK0QAVTwHXjBE6EZr2X2VLj6aVEchkxvuhHAAWOV6r
I81eoHN+6JzyyMwLzsXcfCzGfteJqE0ka7iWL9n6NC0JzIuAPU1LdTMSY9s3qPn5
mRRmwtAKntq+atRVzOhn
=AvEL
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.