Zope ZCatalog Plug-In Remote Method Vulnerability
BID:5812
Info
Zope ZCatalog Plug-In Remote Method Vulnerability
| Bugtraq ID: | 5812 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Sep 25 2002 12:00AM |
| Credit: | Vulnerability announced by the Zope Project. |
| Vulnerable: |
Zope Zope 2.5.1 Zope Zope 2.5 .0 Zope Zope 2.4.4 b1 Zope Zope 2.4.3 Zope Zope 2.4.2 Zope Zope 2.4.1 Zope Zope 2.4 .0 |
| Not Vulnerable: | |
Discussion
Zope ZCatalog Plug-In Remote Method Vulnerability
Zope is a freely available, open source content management system. It is available for Unix, Linux, and Microsoft operating systems.
Under some circumstances, it may be possible for a remote user to take advantage of the plug-ins functionality of ZCatalog, included with the Zope package. Due to insecure default settings, it may be possible for remote users to call arbitrary methods of catalog indexes anonymously.
Zope is a freely available, open source content management system. It is available for Unix, Linux, and Microsoft operating systems.
Under some circumstances, it may be possible for a remote user to take advantage of the plug-ins functionality of ZCatalog, included with the Zope package. Due to insecure default settings, it may be possible for remote users to call arbitrary methods of catalog indexes anonymously.
Exploit / POC
Zope ZCatalog Plug-In Remote Method Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Zope ZCatalog Plug-In Remote Method Vulnerability
Solution:
Debian has released advisory DSA 490-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Fixes available:
Zope Zope 2.4 .0
Zope Zope 2.4.1
Zope Zope 2.4.2
Zope Zope 2.4.3
Zope Zope 2.4.4 b1
Zope Zope 2.5 .0
Zope Zope 2.5.1
Solution:
Debian has released advisory DSA 490-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Fixes available:
Zope Zope 2.4 .0
-
Zope Hotfix_2002-06-14.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-06-14/Hotfix_2002-06-14. tgz
Zope Zope 2.4.1
-
Zope Hotfix_2002-06-14.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-06-14/Hotfix_2002-06-14. tgz
Zope Zope 2.4.2
-
Zope Hotfix_2002-06-14.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-06-14/Hotfix_2002-06-14. tgz
Zope Zope 2.4.3
-
Zope Hotfix_2002-06-14.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-06-14/Hotfix_2002-06-14. tgz
Zope Zope 2.4.4 b1
-
Zope Hotfix_2002-06-14.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-06-14/Hotfix_2002-06-14. tgz
Zope Zope 2.5 .0
-
Zope Hotfix_2002-06-14.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-06-14/Hotfix_2002-06-14. tgz
Zope Zope 2.5.1
-
Debian zope_2.5.1-1woody1_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _alpha.deb -
Debian zope_2.5.1-1woody1_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _arm.deb -
Debian zope_2.5.1-1woody1_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _hppa.deb -
Debian zope_2.5.1-1woody1_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _i386.deb -
Debian zope_2.5.1-1woody1_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _ia64.deb -
Debian zope_2.5.1-1woody1_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _m68k.deb -
Debian zope_2.5.1-1woody1_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _mips.deb -
Debian zope_2.5.1-1woody1_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _mipsel.deb -
Debian zope_2.5.1-1woody1_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _powerpc.deb -
Debian zope_2.5.1-1woody1_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _s390.deb -
Debian zope_2.5.1-1woody1_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/z/zope/zope_2.5.1-1woody1 _sparc.deb -
Zope Hotfix_2002-06-14.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-06-14/Hotfix_2002-06-14. tgz
References
Zope ZCatalog Plug-In Remote Method Vulnerability
References:
References:
- Hotfix 2002-06-14 Alert (Zope)
- Welcome to Zope.org (Zope)