LWN.net Logo

zope: potential code execution

Package(s):zope CVE #(s):CVE-2002-0688
Created:April 21, 2004 Updated:April 21, 2004
Description: The ZCatalog component of the Zope application server can allow anonymous users and untrusted code to call arbitrary methods in the catalog indexes.
Alerts:
Debian DSA-490-1 2004-04-17

(Log in to post comments)

zope: potential code execution

Posted Apr 22, 2004 15:52 UTC (Thu) by tseaver (subscriber, #1544) [Link]

This is hardly a "new" issue; it is more than a year and a half old, with the originial RedHat :

http://www.zope.org/Products/Zope/Hotfix_2002-06-14/security_alert

The original RedHat SA, dated 2002/09/25, on this was covered in LWN:

http://lwn.net/Alerts/10836/

including the LWN security page for that week:

http://lwn.net/Articles/10845/

My comments at the time on the Red Hat report at that time indicated that
*only* the issue now corrected by Debian was even current at that time.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds