LWN.net Logo

zope: Insecure XML-RPC exception handling

Package(s):zope CVE #(s):
Created:October 31, 2002 Updated:October 31, 2002
Description: Zope will reveal the complete physical location where the server and its components are installed if it receives "incorrect" XML-RPC requests.
In some cases it will also reveal information about the serves in the protected LAN (10.x.x.x for example).

More information is available at: http://collector.zope.org/Zope/359

Alerts:
Gentoo zope-20021024 2002-10-24

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds