Re: [ZODB-Dev] CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB ZEO server vulnerabilities

Alexander Limi <limi-z4DKO/[email protected]>
Newsgroups gmane.comp.web.zope.plone.installers
Message-ID <[email protected]>
2009/8/6 Steve McMahon <[email protected]>

> FYI, The current Unified Installer (and OS X) installers for 3.2.x and
> 3.3.x both have 127.0.0.1:8100 for the zeo-address. That should lower
> exposure for common cases.
>
> The Windows installer does not have a ZEO option on install, though folks
> may of course add it after install.


Yup, when we do the announcement, this should be front and center, so people
understand that the standard installers do not have this problem.

Something like:

"If you are using the official Plone installers, you are configured in such
a way that only ZEO instances on your local network can connect, and thus
you are not vulnerable to this. If you constructed your own setup, please
check to make sure that you are not accepting ZEO connections from untrusted
clients."

…or something like that. Modify for correctness etc, I didn't read the
disclosure in full (I'm still on vacation ;)

— Alexander

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july

_______________________________________________
Plone-installers mailing list
Plone-installers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/plone-installers
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.