Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200510-20 ] Zope: File inclusion through RestructuredText
Date: Tue, 25 Oct 2005 11:45:14
Message-Id: 435E17AB.8090809@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200510-20
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Zope: File inclusion through RestructuredText
9 Date: October 25, 2005
10 Bugs: #109087
11 ID: 200510-20
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Zope is vulnerable to a file inclusion vulnerability when exposing
19 RestructuredText functionalities to untrusted users.
20
21 Background
22 ==========
23
24 Zope is an application server that can be used to build content
25 management systems, intranets, portals or other custom applications.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-zope/zope < 2.7.8 >= 2.7.8
34 net-zope/zope == 2.8.0
35 net-zope/zope == 2.8.1
36
37 Description
38 ===========
39
40 Zope honors file inclusion directives in RestructuredText objects by
41 default.
42
43 Impact
44 ======
45
46 An attacker could exploit the vulnerability by sending malicious input
47 that would be interpreted in a RestructuredText Zope object,
48 potentially resulting in the execution of arbitrary Zope code with the
49 rights of the Zope server.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All Zope users should upgrade to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose net-zope/zope
63
64 References
65 ==========
66
67 [ 1 ] Zope Hotfix 2005-10-09 Alert
68 http://www.zope.org/Products/Zope/Hotfix_2005-10-09/security_alert
69
70 Availability
71 ============
72
73 This GLSA and any updates to it are available for viewing at
74 the Gentoo Security Website:
75
76 http://security.gentoo.org/glsa/glsa-200510-20.xml
77
78 Concerns?
79 =========
80
81 Security is a primary focus of Gentoo Linux and ensuring the
82 confidentiality and security of our users machines is of utmost
83 importance to us. Any security concerns should be addressed to
84 security@g.o or alternatively, you may file a bug at
85 http://bugs.gentoo.org.
86
87 License
88 =======
89
90 Copyright 2005 Gentoo Foundation, Inc; referenced text
91 belongs to its owner(s).
92
93 The contents of this document are licensed under the
94 Creative Commons - Attribution / Share Alike license.
95
96 http://creativecommons.org/licenses/by-sa/2.0

Attachments

File name MIME type
signature.asc application/pgp-signature