Re: Fwd: [Zope-Annce] Annoucment: CVE-2010-1104, hotfix, Zope 2.12.22 and 2.13.12 releases.

Patrick Gerken <[email protected]> Thu, 19 Jan 2012 11:49:34 +0100
Newsgroups gmane.comp.web.zope.german
Message-ID <CAFefbnGf7vE+0Lt0xz5gWU0KZXGhpwm+kYO0g5yxaYLs1a8DzQ@mail.gmail.com>
Nein!

Für Zope 2.12 und 2.13 wurden neue Releases rausgegeben, so das man dort
keinen Hotfix einspielen muss, sondern die neueste Zope Minor Version
verwenden muss. Für ältere Zope Versionen, 2.8 - 2.11 MUSS man den Hotfix
einspielen, weil keine neuen Versionen mehr gebaut werden.

Alle Plone 3 Versionen verwenden Zope 2.10,
Alle Plone 4 Versionen verwenden Zope 2.12.

Wer Plone 3 verwendet muss den Hotfix einspielen.
Wer Plone 4 verwendet muss Plone auf die neueste Zope Minor Version
updaten, also Zope 2.12.23, NICHT 2.13.x

Solche minor updates sorgen normalerweise für keine Probleme.

MfG

    Patrick
Am 19.01.2012 11:28 schrieb "Jan Ulrich Hasecke" <[email protected]>:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Hallo Veit,
>
> danke für den Hinweis.
>
> Wenn ich das richtig sehe, muss man den Hotfix nicht anwenden, wenn
> man Zope 2.10.11 hat, wie dies zum Beispiel bei Plone 3.3.5 der Fall ist.
>
> http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1104
>
> Sehe ich das richtig?
>
> juh
>
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.9 (Darwin)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
>
> iEYEARECAAYFAk8X8FMACgkQPUzUEFbILMRuoQCgjfZnD8xRlW1Blh5/Y8LzRX3H
> LxgAnRAEivWg4sKtWb1ObD3K0aNusG6n
> =Qps0
> -----END PGP SIGNATURE-----
>
>
> _______________________________________________
> zope mailing list
> [email protected]
> https://mail.dzug.org/mailman/listinfo/zope
>



_______________________________________________
zope mailing list
[email protected]
https://mail.dzug.org/mailman/listinfo/zope