Re: [ZODB-Dev] CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB ZEO server vulnerabilities
Steve McMahon <[email protected]>
| Newsgroups | gmane.comp.web.zope.plone.installers |
|---|---|
| Message-ID | <[email protected]> |
FYI, The current Unified Installer (and OS X) installers for 3.2.x and 3.3.x both have 127.0.0.1:8100 for the zeo-address. That should lower exposure for common cases. The Windows installer does not have a ZEO option on install, though folks may of course add it after install. On Thu, Aug 6, 2009 at 5:11 AM, Wichert Akkerman <[email protected]> wrote: > How should we handle this? > > Do we need to update installers? > > We should at least communicate this via plone-announce and the website in > some way. > > > -------- Original Message -------- > Subject: [ZODB-Dev] CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB > ZEO server vulnerabilities > Date: Thu, 6 Aug 2009 08:06:32 -0400 > From: Jim Fulton <[email protected]> > To: [email protected] > > Vulnerabilities have been found in the Zope Object Database (ZODB) > Zope Enterprise Objects (ZEO) network protocol that allow: > > CVE-2009-0668 Arbitrary Python code execution in ZODB ZEO storage servers > CVE-2009-0669 Authentication bypass in ZODB ZEO storage servers > > The vulnerabilities only apply if you are using ZEO to share a > database among multiple applications or application instances and if > untrusted clients are able to connect to your ZEO servers. > > The first vulnerability (CVE-2009-0668) was introduced in ZODB 3.3 > (Zope 2.8). The second vulnerability (CVE-2009-0669) was introduced > in ZODB 3.2 (Zope 2.7). > > Overview > > These vulnerabilities are addressed by updates to ZODB. Newer > releases of Zope are also being provided for people who get ZODB with Zope > releases. > > A new release of ZODB is available here: > > http://pypi.python.org/pypi/ZODB3/3.8.2 > > (There is also a new development release at > http://pypi.python.org/pypi/ZODB3/3.9.0b5.) > > New Zope releases that include the fixes can be found here: > > http://www.zope.org/Products/Zope/2.10.9 > http://www.zope.org/Products/Zope/2.11.4 > http://www.zope.org/Products/Zope/2.8.11 > http://www.zope.org/Products/Zope/2.9.11 > http://www.zope.org/Products/Zope3/3.1.1 > http://www.zope.org/Products/Zope3/3.2.4 > http://www.zope.org/Products/Zope3/3.3.3 > http://www.zope.org/Products/Zope3/3.4.1 > > We recommend updating any ZEO storoage servers you're running to ZODB > 3.8.2 (or ZODB 3.9.0b5) or to ZODB software provided with the Zope > releases listed above. These versions support ZEO clients as old as > ZODB 3.2. It isn't necessary to update client software (such as Zope > application servers). > > Restricting access to ZEO storage servers > > It is very important to restrict write access to ZODB databases. These > releases only protect against vulnerabilities in the ZEO network > protocol. ZODB uses Python pickles to store data. Loading data from > the database can cause arbitrary code to be executed as part of object > deserialization. Clients have full access to manipulate database > data. For this reason, it is very important that only trusted clients > be allowed to write to ZODB databases. > > Jim > > -- > Jim Fulton > _______________________________________________ > For more information about ZODB, see the ZODB Wiki: > http://www.zope.org/Wikis/ZODB/ > > ZODB-Dev mailing list - [email protected] > http://mail.zope.org/mailman/listinfo/zodb-dev > -- Steve McMahon Reid-McMahon, LLC steve-HR5nRXif9uVv8oa/[email protected] [email protected] ------------------------------------------------------------------------------ Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day trial. Simplify your report design, integration and deployment - and focus on what you do best, core application coding. Discover what's new with Crystal Reports now. http://p.sf.net/sfu/bobj-july _______________________________________________ Plone-installers mailing list Plone-installers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/plone-installers