Vulnerability in PloneFormGen — Updated announcement

"Announcement of Plone releases and security-related notifications. Recommended subscription for all Plone developers and site admins." <[email protected]> Wed, 29 May 2013 10:26:12 -0700
Newsgroups gmane.comp.web.zope.plone.announce
Message-ID <CAOqzbghiBo4rdKW9xDgK=CrctAVFKiv0Boizdb40rqCdhO-W0Q@mail.gmail.com>
--===============5134820040239393600==
Content-Type: multipart/alternative; boundary=001a11c2e2bce6685504dddeaeb6

--001a11c2e2bce6685504dddeaeb6
Content-Type: text/plain; charset=UTF-8

[The previous version of this announcement suggested an upgrade to
PloneFormGen version 1.7.9. The distribution file for that version had an
error that prevented installation. Version 1.7.11 replaces it. Information
has also been added on how to get help with the update.]

PloneFormGen <http://plone.org/products/ploneformgen>, a widely used
response-form-creation add-on for the Plone Content Management System, has
been discovered to have a serious vulnerability that allows an anonymous
attacker to execute arbitrary code with the privileges of the system user
running the server.

Installations of Plone that do not use the PloneFormGen add-on are not
affected by this vulnerability.

The vulnerability is present in PloneFormGen versions 1.7.4 (2012-11-04)
through 1.7.8. Users of any of these versions should immediately
upgrade to Products.PloneFormGen
version 1.7.11 <https://pypi.python.org/pypi/Products.PloneFormGen/1.7.11>.
1.7.11 has been released today to the Plone and Python package repositories.

Another serious vulnerability affects most earlier versions of
PloneFormGen. This vulnerability affects forms that have custom script
adapters, and allows an anonymous attacker to gain control over the
handling of data submitted through the form. This vulnerability is
addressed in version 1.7.9. Users of PloneFormGen in the 1.6 series, which
runs on Plone 3.x, 4.0 and 4.1 should upgrade to version
1.6.7<https://pypi.python.org/pypi/Products.PloneFormGen/1.6.7>,
also released today.

Help for installing the upgrade is available on the #plone IRC
channel<http://plone.org/support/chat>
 and forums <https://plone.org/support/forums>. Upgrading an already
installed package requires you to specify the new version number in your
buildout configuration
file<https://weblion.psu.edu/trac/weblion/wiki/VersionPinning> and
run buildout.

Thanks to The Code Distillery's security analysts for the responsible
disclosure of the vulnerabilities, and for their suggestions for addressing
the issues.

--001a11c2e2bce6685504dddeaeb6
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div id=3D"content-core">
                                =20
   =20

       =20

       =20

        <div id=3D"parent-fieldname-text" class=3D"">
            <p>[The previous version of this announcement suggested an upgr=
ade to PloneFormGen version 1.7.9. The distribution file for that version h=
ad an error that prevented installation. Version 1.7.11 replaces it. Inform=
ation has also been added on how to get help with the update.]<br>

</p><p><a class=3D"" href=3D"http://plone.org/products/ploneformgen">PloneF=
ormGen</a>,
 a widely used response-form-creation add-on for the Plone Content=20
Management System, has been discovered to have a serious vulnerability=20
that allows an anonymous attacker to execute arbitrary code with the=20
privileges of the system user running the server.</p>
<p>Installations of Plone that do not use the PloneFormGen add-on are not a=
ffected by this vulnerability.</p>
<p>The vulnerability is present in=20
PloneFormGen versions 1.7.4 (2012-11-04) through 1.7.8. Users of any of=20
these versions should immediately upgrade to <a class=3D"" href=3D"https://=
pypi.python.org/pypi/Products.PloneFormGen/1.7.11">Products.PloneFormGen ve=
rsion 1.7.11</a>. 1.7.11 has been released today to the Plone and Python pa=
ckage repositories.</p>


<p>Another serious vulnerability affects=20
most earlier versions of PloneFormGen. This vulnerability affects forms=20
that have custom script adapters, and allows an anonymous attacker to=20
gain control over the handling of data submitted through the form. This=20
vulnerability is addressed in version 1.7.9. Users of PloneFormGen in=20
the 1.6 series, which runs on Plone 3.x, 4.0 and 4.1 should upgrade to <a c=
lass=3D"" href=3D"https://pypi.python.org/pypi/Products.PloneFormGen/1.6.7"=
>version 1.6.7</a>, also released today.</p>
<p>Help for installing the upgrade is available on the=C2=A0<a class=3D"" h=
ref=3D"http://plone.org/support/chat">#plone IRC channel</a>=C2=A0and=C2=A0=
<a class=3D"" href=3D"https://plone.org/support/forums">forums</a>. Upgradi=
ng an already installed package requires you to=C2=A0<a class=3D"" href=3D"=
https://weblion.psu.edu/trac/weblion/wiki/VersionPinning">specify the new v=
ersion number in your buildout configuration file</a>=C2=A0and run buildout=
.</p>

<p>Thanks to The Code Distillery&#39;s security analysts for the responsibl=
e
 disclosure of the vulnerabilities, and for their suggestions for=20
addressing the issues.</p>
<p><br></p>
        </div></div></div>

--001a11c2e2bce6685504dddeaeb6--


--===============5134820040239393600==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Introducing AppDynamics Lite, a free troubleshooting tool for Java/.NET
Get 100% visibility into your production application - at no cost.
Code-level diagnostics for performance bottlenecks with <2% overhead
Download for free and get started troubleshooting in minutes.
http://p.sf.net/sfu/appdyn_d2d_ap1
--===============5134820040239393600==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Plone-Announce mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-announce

--===============5134820040239393600==--