Vulnerability in PloneFormGen requires immediate update

"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Wed, 29 May 2013 09:02:44 -0700
Newsgroups gmane.comp.web.zope.plone.announce
Message-ID <CAOqzbgjyET5+XvHCkbQEmMrkYq6XOFhtiWN4vo1t6_pe+oYoPQ@mail.gmail.com>
--===============6689185829748361147==
Content-Type: multipart/alternative; boundary=089e0112cf64517ec604dddd849a

--089e0112cf64517ec604dddd849a
Content-Type: text/plain; charset=UTF-8

PloneFormGen, a widely used response-form-creation add-on for the Plone
Content Management System, has been discovered to have a serious
vulnerability that allows an anonymous attacker to execute arbitrary code
with the privileges of the system user running the server.

Installations of Plone that do not use the PloneFormGen add-on are not
affected by this vulnerability.

The vulnerability is present in PloneFormGen versions 1.7.4 (2012-11-04)
through 1.7.8. Users of any of these versions should immediately upgrade to
Products.PloneFormGen version 1.7.9. 1.7.9 has been released today to the
Plone and Python package repositories.

Another serious vulnerability affects most earlier versions of
PloneFormGen. This vulnerability affects forms that have custom script
adapters, and allows an anonymous attacker to gain control over the
handling of data submitted through the form. This vulnerability is
addressed in version 1.7.9. Users of PloneFormGen in the 1.6 series, which
runs on Plone 3.x, 4.0 and 4.1 should upgrade to version 1.6.7, also
released today.

Thanks to The Code Distillery's security analysts for the responsible
disclosure of the vulnerabilities, and for their suggestions for addressing
the issues.

--089e0112cf64517ec604dddd849a
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"im" style=3D"font-family:arial,sans-serif;fo=
nt-size:13.333333969116211px">PloneFormGen, a widely used response-form-cre=
ation add-on for the Plone Content Management System, has been discovered t=
o have a serious vulnerability that allows an anonymous attacker to execute=
 arbitrary code with the privileges of the system user running the server.<=
/div>

<div class=3D"im" style=3D"font-family:arial,sans-serif;font-size:13.333333=
969116211px"><br></div><div class=3D"im" style=3D"font-family:arial,sans-se=
rif;font-size:13.333333969116211px">Installations of Plone that do not use =
the PloneFormGen add-on are not affected by this vulnerability.<br>

<div><div><br></div><div>The vulnerability is present in PloneFormGen versi=
ons 1.7.4 (2012-11-04) through 1.7.8. Users of any of these versions should=
 immediately upgrade to Products.PloneFormGen version 1.7.9. 1.7.9 has been=
 released today to the Plone and Python package repositories.</div>

<div><br></div></div><div>Another serious vulnerability affects most earlie=
r versions of PloneFormGen. This vulnerability affects forms that have cust=
om script adapters, and allows an anonymous attacker to gain control over t=
he handling of data submitted through the form. This vulnerability is addre=
ssed in version 1.7.9. Users of PloneFormGen in the 1.6 series, which runs =
on Plone 3.x, 4.0 and 4.1 should upgrade to version 1.6.7, also released to=
day.</div>

</div><div style=3D"font-family:arial,sans-serif;font-size:13.3333339691162=
11px"><div><br></div><div class=3D"im">Thanks to The Code Distillery&#39;s =
security analysts for the responsible disclosure of the vulnerabilities, an=
d for their suggestions for addressing the issues.</div>

</div></div>

--089e0112cf64517ec604dddd849a--


--===============6689185829748361147==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Introducing AppDynamics Lite, a free troubleshooting tool for Java/.NET
Get 100% visibility into your production application - at no cost.
Code-level diagnostics for performance bottlenecks with <2% overhead
Download for free and get started troubleshooting in minutes.
http://p.sf.net/sfu/appdyn_d2d_ap1
--===============6689185829748361147==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce

--===============6689185829748361147==--