Security: Potential mail header vulnerability

plone-announce-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org Fri, 14 May 2004 04:03:48 +0200
Newsgroups gmane.comp.web.zope.plone.announce
Organization Plone Solutions · http://www.plonesolu tions.com
Message-ID <[email protected]>
Plone 2.0 has a bug that makes it potentially possible to insert extra  
headers in mail via the Send To form.

To fix this, either

- Upgrade to the "2.0.2 release":plone-2.0.2-released *or*

- Download the simple fix:

   http://plone.org/documentation/errata/Plone-2.0-headerfix.zip (8 KB)

   and unpack into your Plone install and restart your Plone server. Full  
instructions included, copying two files to the correct location will fix  
it.

**No other Plone versions than 2.0 is affected by this. Plone 1.0.x sites  
are not vulnerable.**

**The header insertion is not possible to do from a web browser, it needs  
to be scripted to be possible at all.**

There is one reported site that has been the victim of this problem,  
thanks to John Ferlito for discovering and analysing the problem  
thoroughly.

Thanks to Christian Heimes (Tiran), Leonard Norrgård (vinsci) and Geoff  
Davis (geoffd) for their extremely swift response and testing/fixing. The  
bug was fixed in CVS within 48 hours after being reported.

On behalf of the Plone Team,

-- 
__________________________________________________________________

  Alexander Limi    ·     Chief Architect     ·    Plone Solutions

  Development · Training · Support · http://www.plonesolutions.com
__________________________________________________________________

  Plone Co-Founder   ·   http://plone.org   ·   Connecting Content


-------------------------------------------------------
This SF.Net email is sponsored by: SourceForge.net Broadband
Sign-up now for SourceForge Broadband and get the fastest
6.0/768 connection for only $19.95/mo for the first 3 months!
http://ads.osdn.com/?ad_id%62&alloc_ida84&op=click