Zope CSV_Table Information Disclosure Vulnerability
BID:20022
CVE-2006-4684 |Info
Zope CSV_Table Information Disclosure Vulnerability
| Bugtraq ID: | 20022 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4684 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2006 12:00AM |
| Updated: | Dec 19 2006 06:22PM |
| Credit: | This issue was disclosed in the referenced Debian advisory. |
| Vulnerable: |
Zope Zope 2.8.8 Zope Zope 2.7.5 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
Zope CSV_Table Information Disclosure Vulnerability
Zope is prone to an information-disclosure vulnerability because the application fails to properly secure potentially sensitive information.
A remote attacker can exploit this issue to retrieve potentially sensitive information that may aid the attacker in further attacks.
Zope is prone to an information-disclosure vulnerability because the application fails to properly secure potentially sensitive information.
A remote attacker can exploit this issue to retrieve potentially sensitive information that may aid the attacker in further attacks.
Exploit / POC
Zope CSV_Table Information Disclosure Vulnerability
Attackers can exploit this issue through a web client.
Attackers can exploit this issue through a web client.
Solution / Fix
Zope CSV_Table Information Disclosure Vulnerability
Solution:
Please see the referenced advisories for more information.
Zope Zope 2.7.5
Solution:
Please see the referenced advisories for more information.
Zope Zope 2.7.5
-
Debian zope2.7_2.7.5-2sarge3_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_alpha.deb -
Debian zope2.7_2.7.5-2sarge3_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_amd64.deb -
Debian zope2.7_2.7.5-2sarge3_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_arm.deb -
Debian zope2.7_2.7.5-2sarge3_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_hppa.deb -
Debian zope2.7_2.7.5-2sarge3_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_i386.deb -
Debian zope2.7_2.7.5-2sarge3_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_ia64.deb -
Debian zope2.7_2.7.5-2sarge3_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_m68k.deb -
Debian zope2.7_2.7.5-2sarge3_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_mips.deb -
Debian zope2.7_2.7.5-2sarge3_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_mipsel.deb -
Debian zope2.7_2.7.5-2sarge3_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_powerpc.deb -
Debian zope2.7_2.7.5-2sarge3_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_s390.deb -
Debian zope2.7_2.7.5-2sarge3_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/z/zope2.7/zope2.7_2.7.5-2 sarge3_sparc.deb