User: Password:
|
|
Subscribe / Log in / New account

zope: privilege escalation

Package(s):zope CVE #(s):CVE-2006-3458
Created:July 13, 2006 Updated:August 9, 2006
Description: Zope version 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 has a privilege escalation vulnerability related to its failure to deactivate the raw command. Remote users with privileges to edit zope pages with RestructuredText can cause arbitrary files to become exposed.
Alerts:
SuSE SUSE-SR:2006:019 fbi gimp libwmf X.org zope horde 2006-08-09
Debian DSA-1113-1 zope2.7 2006-07-18
Ubuntu USN-317-1 zope2.8 2006-07-13

(Log in to post comments)

zope: privilege escalation (NOT!)

Posted Jul 21, 2006 19:22 UTC (Fri) by tseaver (guest, #1544) [Link]

This vulnerability is an "information disclosure" problem, not a "privilege escalation": as the Ubuntu alert notes:

A remote user with the privilege of editing Zope webpages with RestructuredText could exploit this to expose arbitrary files that can be read with the privileges of the Zope server.

The original announcement includes a hotfix product, which it recommends deploying on any Zope instance which cannot be upgraded to a recent version of Zope.

I did the analysis, wrote the hotfix product, and checked in the fixes.


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds