CVE-2006-3458
Summary
| CVE | CVE-2006-3458 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-07 23:05:00 UTC |
| Updated | 2018-10-03 21:43:00 UTC |
| Description | Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zope | Zope | 2.7.0 | All | All | All |
| Application | Zope | Zope | 2.7.1 | All | All | All |
| Application | Zope | Zope | 2.7.2 | All | All | All |
| Application | Zope | Zope | 2.7.3 | All | All | All |
| Application | Zope | Zope | 2.7.4 | All | All | All |
| Application | Zope | Zope | 2.7.5 | All | All | All |
| Application | Zope | Zope | 2.7.6 | All | All | All |
| Application | Zope | Zope | 2.7.7 | All | All | All |
| Application | Zope | Zope | 2.7.8 | All | All | All |
| Application | Zope | Zope | 2.8.0 | All | All | All |
| Application | Zope | Zope | 2.8.1 | All | All | All |
| Application | Zope | Zope | 2.8.2 | All | All | All |
| Application | Zope | Zope | 2.8.3 | All | All | All |
| Application | Zope | Zope | 2.8.4 | All | All | All |
| Application | Zope | Zope | 2.8.5 | All | All | All |
| Application | Zope | Zope | 2.8.6 | All | All | All |
| Application | Zope | Zope | 2.8.7 | All | All | All |
| Application | Zope | Zope | 2.9.0 | All | All | All |
| Application | Zope | Zope | 2.9.1 | All | All | All |
| Application | Zope | Zope | 2.9.2 | All | All | All |
| Application | Zope | Zope | 2.9.3 | All | All | All |
| Application | Zope | Zope | 2.7.0 | All | All | All |
| Application | Zope | Zope | 2.7.1 | All | All | All |
| Application | Zope | Zope | 2.7.2 | All | All | All |
| Application | Zope | Zope | 2.7.3 | All | All | All |
| Application | Zope | Zope | 2.7.4 | All | All | All |
| Application | Zope | Zope | 2.7.5 | All | All | All |
| Application | Zope | Zope | 2.7.6 | All | All | All |
| Application | Zope | Zope | 2.7.7 | All | All | All |
| Application | Zope | Zope | 2.7.8 | All | All | All |
| Application | Zope | Zope | 2.8.0 | All | All | All |
| Application | Zope | Zope | 2.8.1 | All | All | All |
| Application | Zope | Zope | 2.8.2 | All | All | All |
| Application | Zope | Zope | 2.8.3 | All | All | All |
| Application | Zope | Zope | 2.8.4 | All | All | All |
| Application | Zope | Zope | 2.8.5 | All | All | All |
| Application | Zope | Zope | 2.8.6 | All | All | All |
| Application | Zope | Zope | 2.8.7 | All | All | All |
| Application | Zope | Zope | 2.9.0 | All | All | All |
| Application | Zope | Zope | 2.9.1 | All | All | All |
| Application | Zope | Zope | 2.9.2 | All | All | All |
| Application | Zope | Zope | 2.9.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-1113-1 zope2.7 | DEBIAN | www.debian.org | |
| 404 Not Found | CONFIRM | www.zope.org | |
| Zope Docutils Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| Secunia - Advisories - Zope reStructuredText "raw" Directive Information Disclosure | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Debian update for zope - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| SUSE Updates for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Ubuntu update for zope - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| USN-317-1: zope2.8 vulnerability | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Security Announcement | SUSE | www.novell.com | |
| [Zope-Annce] Serious security problem with Zope 2 | MLIST | mail.zope.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.