Fwd: [Zope-Annce] Annoucment: CVE-2010-1104, hotfix, Zope 2.12.22 and 2.13.12 releases
Veit Schiele <[email protected]> Thu, 19 Jan 2012 10:36:39 +0100
| Newsgroups | gmane.comp.web.zope.german |
|---|---|
| Organization | Veit Schiele Communications GmbH |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 FYI: - - -------- Original-Nachricht -------- Betreff: [Zope-Annce] Annoucment: CVE-2010-1104, hotfix, Zope 2.12.22 and 2.13.12 releases Datum: Wed, 18 Jan 2012 17:30:30 -0500 Von: Tres Seaver <[email protected]> An: [email protected], [email protected], Zope Developers <[email protected]>, [email protected] Overview ======== In response to the cross-site scripting vulnerability in Zope2 reported as 'CVE 2010-1104'[1], the Zope security response team announces the availablility of a hotfix product (for Zope < 2.12), and new releases for the Zope 2.12 and 2.13 lines: Hotfix: http://pypi.python.org/pypi/Products.Zope_Hotfix_CVE_2010_1104 Zope 2.12.22: http://pypi.python.org/pypi/Zope2/2.12.22 Zope 2.13.12: http://pypi.python.org/pypi/Zope2/2.13.12 WARNING: Zope < 2.12 is no longer officially supported, and may have other unpatched vulnerabilities. You are encouraged to upgrade to a supported Zope 2. Installing the Hotfix ===================== The hotfix has been tested with Zope instances using Zope 2.8.x - 2.11.x. Users of Zope 2.12.x and 2.13.x should instead update to the latest corresponding minor revision, which already includes this fix. Download the tarball from the PyPI page: http://pypi.python.org/pypi/Products.Zope_Hotfix_CVE_2010_1104 Unpack the tarball and add a 'products' key to the 'etc/zope.conf' of your instance. E.g.:: products /path/to/Products.Zope_Hotfix_CVE_2010_1104/Products and restart. Alternatively, you may copy or symlink the 'Products' directory into the 'Products' subdirectory of your Zope instance. E.g.:: $ cp -r /path/to/Products.Zope_Hotfix_CVE_2010_1104/Products \ /path/to/instance/Products/ Verifying the Installation - - -------------------------- After restarting the Zope instance, check the 'Control_Panel/Products' folder in the Zope Management Interface, e.g.: http://localhost:8080/Control_Panel/Products/manage_main You should see the 'Zope_Hotfix_CVE_2010_1104' product folder there. [1] http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1104 Tres. _______________________________________________ Zope-Announce maillist - [email protected] https://mail.zope.org/mailman/listinfo/zope-announce Zope-Announce for Announcements only - no discussions (Related lists - Users: https://mail.zope.org/mailman/listinfo/zope Developers: https://mail.zope.org/mailman/listinfo/zope-dev ) - -- Veit Schiele Communications GmbH Amtsgericht Berlin (Charlottenburg): HRB 137927 B Geschäftsführer: Veit Schiele Mansteinstr. 7 D-10783 Berlin Tel: +49 30 8185667-1 Fax: +49 30 8185667-3 http://www.veit-schiele.de -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (Darwin) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk8X5CUACgkQiRID92Ub+UYqEgCfe4Ovzx/e2m1lOVzcs0zA3xv7 kqoAn0puthQs7Oqcqn6zVe+nkJDqNciz =AbBL -----END PGP SIGNATURE----- _______________________________________________ zope mailing list [email protected] https://mail.dzug.org/mailman/listinfo/zope