Re: Fwd: [Zope-Annce] Annoucment: CVE-2010-1104, hotfix, Zope 2.12.22 and 2.13.12 releases

Jan Ulrich Hasecke <[email protected]> Thu, 19 Jan 2012 11:54:46 +0100
Newsgroups gmane.comp.web.zope.german
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Am 19.01.12 11:32, schrieb Kristian Thy:
> On Thu, Jan 19, Jan Ulrich Hasecke wrote:
>> Wenn ich das richtig sehe, muss man den Hotfix nicht anwenden,
>> wenn man Zope 2.10.11 hat, wie dies zum Beispiel bei Plone 3.3.5
>> der Fall ist.
>> 
>> http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1104
>> 
>> Sehe ich das richtig?
> 
> Nein. 2.10.11 < 2.12!
> 
> \\kristian

Ich verstehe das anders:

"""
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12,
2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and
2.12.x before 2.12.3 allows remote attackers to inject arbitrary web
script or HTML via vectors related to error messages.
"""

"20.10.x before 2.10.11"

2.10.11 wäre damit nicht betroffen.

Mit freundlichen Grüßen
Jan Ulrich Hasecke

- -- 
http://hasecke.com * Business Communication
Werbung für den Mittelstand | Text- und Präsentationsseminare
Schubertstr. 4 * 42719 Solingen * Telefon ++49-212-2331483
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk8X9nEACgkQPUzUEFbILMSs1gCeIhPYoJXuj4MuNuL9lTof7hNX
12wAn1coFAUVIgpQFaG1kV5YC7qJTF9b
=Yigz
-----END PGP SIGNATURE-----


_______________________________________________
zope mailing list
[email protected]
https://mail.dzug.org/mailman/listinfo/zope