LWN.net Logo

zope: privilege escalation (NOT!)

zope: privilege escalation (NOT!)

Posted Jul 21, 2006 19:22 UTC (Fri) by tseaver (subscriber, #1544)
Parent article: zope: privilege escalation

This vulnerability is an "information disclosure" problem, not a "privilege escalation": as the Ubuntu alert notes:

A remote user with the privilege of editing Zope webpages with RestructuredText could exploit this to expose arbitrary files that can be read with the privileges of the Zope server.

The original announcement includes a hotfix product, which it recommends deploying on any Zope instance which cannot be upgraded to a recent version of Zope.

I did the analysis, wrote the hotfix product, and checked in the fixes.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds