Security: Potential mail header vulnerability
plone-announce-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org Fri, 14 May 2004 04:03:48 +0200
| Newsgroups | gmane.comp.web.zope.plone.announce |
|---|---|
| Organization | Plone Solutions · http://www.plonesolu tions.com |
| Message-ID | <[email protected]> |
Plone 2.0 has a bug that makes it potentially possible to insert extra headers in mail via the Send To form. To fix this, either - Upgrade to the "2.0.2 release":plone-2.0.2-released *or* - Download the simple fix: http://plone.org/documentation/errata/Plone-2.0-headerfix.zip (8 KB) and unpack into your Plone install and restart your Plone server. Full instructions included, copying two files to the correct location will fix it. **No other Plone versions than 2.0 is affected by this. Plone 1.0.x sites are not vulnerable.** **The header insertion is not possible to do from a web browser, it needs to be scripted to be possible at all.** There is one reported site that has been the victim of this problem, thanks to John Ferlito for discovering and analysing the problem thoroughly. Thanks to Christian Heimes (Tiran), Leonard Norrgård (vinsci) and Geoff Davis (geoffd) for their extremely swift response and testing/fixing. The bug was fixed in CVS within 48 hours after being reported. On behalf of the Plone Team, -- __________________________________________________________________ Alexander Limi · Chief Architect · Plone Solutions Development · Training · Support · http://www.plonesolutions.com __________________________________________________________________ Plone Co-Founder · http://plone.org · Connecting Content ------------------------------------------------------- This SF.Net email is sponsored by: SourceForge.net Broadband Sign-up now for SourceForge Broadband and get the fastest 6.0/768 connection for only $19.95/mo for the first 3 months! http://ads.osdn.com/?ad_id%62&alloc_ida84&op=click