Fwd: [Zope-Annce] Annoucment: CVE-2010-1104, hotfix, Zope 2.12.22 and 2.13.12 releases

Veit Schiele <[email protected]> Thu, 19 Jan 2012 10:36:39 +0100
Newsgroups gmane.comp.web.zope.german
Organization Veit Schiele Communications GmbH
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

FYI:

- - -------- Original-Nachricht --------
Betreff:     [Zope-Annce] Annoucment: CVE-2010-1104, hotfix, Zope
2.12.22 and 2.13.12 releases
Datum:     Wed, 18 Jan 2012 17:30:30 -0500
Von:     Tres Seaver <[email protected]>
An:     [email protected], [email protected], Zope Developers
<[email protected]>, [email protected]



Overview
========

In response to the cross-site scripting vulnerability in Zope2 reported
as 'CVE 2010-1104'[1], the Zope security response team announces the
availablility of a hotfix product (for Zope < 2.12), and new releases
for the Zope 2.12 and 2.13 lines:

Hotfix:  http://pypi.python.org/pypi/Products.Zope_Hotfix_CVE_2010_1104

Zope 2.12.22:  http://pypi.python.org/pypi/Zope2/2.12.22

Zope 2.13.12:  http://pypi.python.org/pypi/Zope2/2.13.12


WARNING: Zope < 2.12 is no longer officially supported, and may have
         other unpatched vulnerabilities. You are encouraged to
         upgrade to a supported Zope 2.


Installing the Hotfix
=====================

The hotfix has been tested with Zope instances using Zope 2.8.x - 2.11.x.
Users of Zope 2.12.x and 2.13.x should instead update to the latest
corresponding minor revision, which already includes this fix.

Download the tarball from the PyPI page:

 http://pypi.python.org/pypi/Products.Zope_Hotfix_CVE_2010_1104

Unpack the tarball and add a 'products' key to the 'etc/zope.conf' of
your instance.  E.g.::

  products /path/to/Products.Zope_Hotfix_CVE_2010_1104/Products

and restart.  Alternatively, you may copy or symlink the 'Products'
directory into the 'Products' subdirectory of your Zope instance.  E.g.::

  $ cp -r /path/to/Products.Zope_Hotfix_CVE_2010_1104/Products \
    /path/to/instance/Products/


Verifying the Installation
- - --------------------------

After restarting the Zope instance, check the
'Control_Panel/Products' folder in the Zope Management Interface,
e.g.:

  http://localhost:8080/Control_Panel/Products/manage_main

You should see the 'Zope_Hotfix_CVE_2010_1104' product folder there.




[1] http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1104



Tres.
_______________________________________________
Zope-Announce maillist  -  [email protected]
https://mail.zope.org/mailman/listinfo/zope-announce

  Zope-Announce for Announcements only - no discussions

(Related lists -
 Users: https://mail.zope.org/mailman/listinfo/zope
 Developers: https://mail.zope.org/mailman/listinfo/zope-dev )



- -- 
Veit Schiele Communications GmbH
Amtsgericht Berlin (Charlottenburg): HRB 137927 B
Geschäftsführer: Veit Schiele

Mansteinstr. 7
D-10783 Berlin
Tel: +49 30 8185667-1
Fax: +49 30 8185667-3
http://www.veit-schiele.de
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk8X5CUACgkQiRID92Ub+UYqEgCfe4Ovzx/e2m1lOVzcs0zA3xv7
kqoAn0puthQs7Oqcqn6zVe+nkJDqNciz
=AbBL
-----END PGP SIGNATURE-----


_______________________________________________
zope mailing list
[email protected]
https://mail.dzug.org/mailman/listinfo/zope