Zope Docutils Information Disclosure Vulnerability
BID:18856
CVE-2006-3458 |Info
Zope Docutils Information Disclosure Vulnerability
| Bugtraq ID: | 18856 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3458 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2006 12:00AM |
| Updated: | Sep 04 2006 07:13PM |
| Credit: | Tres Seaver is credited with the discovery of this vulnerability. |
| Vulnerable: |
Zope Zope 2.9.3 Zope Zope 2.9.2 Zope Zope 2.9.1 Zope Zope 2.9 Zope Zope 2.8.7 Zope Zope 2.8.6 Zope Zope 2.8.5 Zope Zope 2.8.4 Zope Zope 2.8.3 Zope Zope 2.8.2 Zope Zope 2.8.1 Zope Zope 2.7.8 Zope Zope 2.7.7 Zope Zope 2.7.6 Zope Zope 2.7.5 Zope Zope 2.7.4 Zope Zope 2.7.3 Zope Zope 2.7.2 Zope Zope 2.7.1 Zope Zope 2.7 .0 BETA4 Zope Zope 2.7 .0 BETA3 Zope Zope 2.7 .0 BETA2 Zope Zope 2.7 .0 BETA1 Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Office Server S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Zope Docutils Information Disclosure Vulnerability
Zope is prone to an information-disclosure vulnerability.
This issue is due to an error in the 'docutils' module when parsing and rendering text.
An attacker can exploit this issue by creating a web page with restructured text to access arbitrary files.
Versions 2.7.0 to 2.9.3 are vulnerable.
Zope is prone to an information-disclosure vulnerability.
This issue is due to an error in the 'docutils' module when parsing and rendering text.
An attacker can exploit this issue by creating a web page with restructured text to access arbitrary files.
Versions 2.7.0 to 2.9.3 are vulnerable.
Exploit / POC
Zope Docutils Information Disclosure Vulnerability
Attackers can exploit this issue through a web client.
Attackers can exploit this issue through a web client.
Solution / Fix
Zope Docutils Information Disclosure Vulnerability
Solution:
The vendor has released a fix to address this issue.
Please see the references for vendor advisories and more information.
Zope Zope 2.7.5
Zope Zope 2.8.1
Solution:
The vendor has released a fix to address this issue.
Please see the references for vendor advisories and more information.
Zope Zope 2.7.5
-
Debian zope2.7_2.7.5-2sarge2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_alpha.deb -
Debian zope2.7_2.7.5-2sarge2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_amd64.deb -
Debian zope2.7_2.7.5-2sarge2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_arm.deb -
Debian zope2.7_2.7.5-2sarge2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_hppa.deb -
Debian zope2.7_2.7.5-2sarge2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_i386.deb -
Debian zope2.7_2.7.5-2sarge2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_ia64.deb -
Debian zope2.7_2.7.5-2sarge2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_m68k.deb -
Debian zope2.7_2.7.5-2sarge2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_mips.deb -
Debian zope2.7_2.7.5-2sarge2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_mipsel.deb -
Debian zope2.7_2.7.5-2sarge2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_powerpc.deb -
Debian zope2.7_2.7.5-2sarge2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_s390.deb -
Debian zope2.7_2.7.5-2sarge2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge2_sparc.deb
Zope Zope 2.8.1
-
Ubuntu zope2.8-sandbox_2.8.1-5ubuntu0.2_all.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/z/zope2.8/zope2.8-sandbox_ 2.8.1-5ubuntu0.2_all.deb -
Ubuntu zope2.8_2.8.1-5ubuntu0.2_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/z/zope2.8/zope2.8_2.8.1-5u buntu0.2_amd64.deb -
Ubuntu zope2.8_2.8.1-5ubuntu0.2_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/z/zope2.8/zope2.8_2.8.1-5u buntu0.2_i386.deb -
Ubuntu zope2.8_2.8.1-5ubuntu0.2_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/z/zope2.8/zope2.8_2.8.1-5u buntu0.2_powerpc.deb -
Ubuntu zope2.8_2.8.1-5ubuntu0.2_sparc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/z/zope2.8/zope2.8_2.8.1-5u buntu0.2_sparc.deb
References
Zope Docutils Information Disclosure Vulnerability
References:
References:
- Zope Announcement 2006-2681 (Zope)
- Zope Home Page (Zope)