Re: [ZODB-Dev] CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB ZEO server vulnerabilities
Alexander Limi <limi-z4DKO/[email protected]>
| Newsgroups | gmane.comp.web.zope.plone.installers |
|---|---|
| Message-ID | <[email protected]> |
2009/8/6 Steve McMahon <[email protected]> > FYI, The current Unified Installer (and OS X) installers for 3.2.x and > 3.3.x both have 127.0.0.1:8100 for the zeo-address. That should lower > exposure for common cases. > > The Windows installer does not have a ZEO option on install, though folks > may of course add it after install. Yup, when we do the announcement, this should be front and center, so people understand that the standard installers do not have this problem. Something like: "If you are using the official Plone installers, you are configured in such a way that only ZEO instances on your local network can connect, and thus you are not vulnerable to this. If you constructed your own setup, please check to make sure that you are not accepting ZEO connections from untrusted clients." …or something like that. Modify for correctness etc, I didn't read the disclosure in full (I'm still on vacation ;) — Alexander ------------------------------------------------------------------------------ Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day trial. Simplify your report design, integration and deployment - and focus on what you do best, core application coding. Discover what's new with Crystal Reports now. http://p.sf.net/sfu/bobj-july _______________________________________________ Plone-installers mailing list Plone-installers-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/plone-installers