Re: Fwd: [Zope-Annce] Annoucment: CVE-2010-1104, hotfix, Zope 2.12.22 and 2.13.12 releases
Jan Ulrich Hasecke <[email protected]> Thu, 19 Jan 2012 11:54:46 +0100
| Newsgroups | gmane.comp.web.zope.german |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Am 19.01.12 11:32, schrieb Kristian Thy: > On Thu, Jan 19, Jan Ulrich Hasecke wrote: >> Wenn ich das richtig sehe, muss man den Hotfix nicht anwenden, >> wenn man Zope 2.10.11 hat, wie dies zum Beispiel bei Plone 3.3.5 >> der Fall ist. >> >> http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1104 >> >> Sehe ich das richtig? > > Nein. 2.10.11 < 2.12! > > \\kristian Ich verstehe das anders: """ Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages. """ "20.10.x before 2.10.11" 2.10.11 wäre damit nicht betroffen. Mit freundlichen Grüßen Jan Ulrich Hasecke - -- http://hasecke.com * Business Communication Werbung für den Mittelstand | Text- und Präsentationsseminare Schubertstr. 4 * 42719 Solingen * Telefon ++49-212-2331483 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (Darwin) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAk8X9nEACgkQPUzUEFbILMSs1gCeIhPYoJXuj4MuNuL9lTof7hNX 12wAn1coFAUVIgpQFaG1kV5YC7qJTF9b =Yigz -----END PGP SIGNATURE----- _______________________________________________ zope mailing list [email protected] https://mail.dzug.org/mailman/listinfo/zope