Re: [ZODB-Dev] CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB ZEO server vulnerabilities

Steve McMahon <[email protected]>
Newsgroups gmane.comp.web.zope.plone.installers
Message-ID <[email protected]>
FYI, The current Unified Installer (and OS X) installers for 3.2.x and 3.3.x
both have 127.0.0.1:8100 for the zeo-address. That should lower exposure for
common cases.

The Windows installer does not have a ZEO option on install, though folks
may of course add it after install.

On Thu, Aug 6, 2009 at 5:11 AM, Wichert Akkerman <[email protected]> wrote:

> How should we handle this?
>
> Do we need to update installers?
>
> We should at least communicate this via plone-announce and the website in
> some way.
>
>
> -------- Original Message --------
> Subject: [ZODB-Dev] CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB
>  ZEO server vulnerabilities
> Date: Thu, 6 Aug 2009 08:06:32 -0400
> From: Jim Fulton <[email protected]>
> To: [email protected]
>
> Vulnerabilities have been found in the Zope Object Database (ZODB)
> Zope Enterprise Objects (ZEO) network protocol that allow:
>
>  CVE-2009-0668 Arbitrary Python code execution in ZODB ZEO storage servers
>  CVE-2009-0669 Authentication bypass in ZODB ZEO storage servers
>
> The vulnerabilities only apply if you are using ZEO to share a
> database among multiple applications or application instances and if
> untrusted clients are able to connect to your ZEO servers.
>
> The first vulnerability (CVE-2009-0668) was introduced in ZODB 3.3
> (Zope 2.8).  The second vulnerability (CVE-2009-0669) was introduced
> in ZODB 3.2 (Zope 2.7).
>
> Overview
>
> These vulnerabilities are addressed by updates to ZODB.  Newer
> releases of Zope are also being provided for people who get ZODB with Zope
> releases.
>
> A new release of ZODB is available here:
>
>  http://pypi.python.org/pypi/ZODB3/3.8.2
>
>  (There is also a new development release at
>   http://pypi.python.org/pypi/ZODB3/3.9.0b5.)
>
> New Zope releases that include the fixes can be found here:
>
>  http://www.zope.org/Products/Zope/2.10.9
>  http://www.zope.org/Products/Zope/2.11.4
>  http://www.zope.org/Products/Zope/2.8.11
>  http://www.zope.org/Products/Zope/2.9.11
>  http://www.zope.org/Products/Zope3/3.1.1
>  http://www.zope.org/Products/Zope3/3.2.4
>  http://www.zope.org/Products/Zope3/3.3.3
>  http://www.zope.org/Products/Zope3/3.4.1
>
> We recommend updating any ZEO storoage servers you're running to ZODB
> 3.8.2 (or ZODB 3.9.0b5) or to ZODB software provided with the Zope
> releases listed above.  These versions support ZEO clients as old as
> ZODB 3.2. It isn't necessary to update client software (such as Zope
> application servers).
>
> Restricting access to ZEO storage servers
>
> It is very important to restrict write access to ZODB databases.  These
> releases only protect against vulnerabilities in the ZEO network
> protocol. ZODB uses Python pickles to store data. Loading data from
> the database can cause arbitrary code to be executed as part of object
> deserialization.  Clients have full access to manipulate database
> data.  For this reason, it is very important that only trusted clients
> be allowed to write to ZODB databases.
>
> Jim
>
> --
> Jim Fulton
> _______________________________________________
> For more information about ZODB, see the ZODB Wiki:
> http://www.zope.org/Wikis/ZODB/
>
> ZODB-Dev mailing list  -  [email protected]
> http://mail.zope.org/mailman/listinfo/zodb-dev
>



-- 

Steve McMahon
Reid-McMahon, LLC
steve-HR5nRXif9uVv8oa/[email protected]
[email protected]

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july

_______________________________________________
Plone-installers mailing list
Plone-installers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/plone-installers
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.