Zope DTML Editing Vulnerability
BID:922
Info
Zope DTML Editing Vulnerability
| Bugtraq ID: | 922 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2000 12:00AM |
| Updated: | Dec 08 2000 12:00AM |
| Credit: | This vulnerability was discovered by Aleksander Salwa, and announced to the Zope mailing list by Brian Lloyd <[email protected]> on December 8, 2000. |
| Vulnerable: |
Zope Zope 2.2.4 Zope Zope 2.2.3 Zope Zope 2.2.2 Zope Zope 2.2.1 Zope Zope 2.2 .0 |
| Not Vulnerable: | |
Discussion
Zope DTML Editing Vulnerability
Zope is a freely available dynamic web page management suite, written and maintained by the Zope Project. A problem exists which could allow a user access to unauthorized resources.
The problem occurs in the handling of legacy file names. Insufficent access control on certain DTML Method objects make it possible to anonymous remote users to create new objects and DTML Method instances. This would allow a malicious user to potentially create new methods and possibly retrieve information from a system running Zope. It could also potentially result in a compromise of data being handled by Zope. This vulnerability affects Zope software revisions 2.2.0 thru 2.2.4.
Zope is a freely available dynamic web page management suite, written and maintained by the Zope Project. A problem exists which could allow a user access to unauthorized resources.
The problem occurs in the handling of legacy file names. Insufficent access control on certain DTML Method objects make it possible to anonymous remote users to create new objects and DTML Method instances. This would allow a malicious user to potentially create new methods and possibly retrieve information from a system running Zope. It could also potentially result in a compromise of data being handled by Zope. This vulnerability affects Zope software revisions 2.2.0 thru 2.2.4.
Exploit / POC
Zope DTML Editing Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Zope DTML Editing Vulnerability
Solution:
Updates available:
Zope Zope 2.2 .0
Zope Zope 2.2.1
Zope Zope 2.2.2
Zope Zope 2.2.3
Zope Zope 2.2.4
Solution:
Updates available:
Zope Zope 2.2 .0
-
Zope Zope 2.2.4 Hotfix_2000-12-08.tgz
This is for the Zope software package released 2.2.0 thru 2.2.4.
http://www.zope.org/Products/Zope/Hotfix_2000-12-08/Hotfix_2000-12-08. tgz
Zope Zope 2.2.1
-
Zope Zope 2.2.4 Hotfix_2000-12-08.tgz
This is for the Zope software package released 2.2.0 thru 2.2.4.
http://www.zope.org/Products/Zope/Hotfix_2000-12-08/Hotfix_2000-12-08. tgz
Zope Zope 2.2.2
-
Zope Zope 2.2.4 Hotfix_2000-12-08.tgz
This is for the Zope software package released 2.2.0 thru 2.2.4.
http://www.zope.org/Products/Zope/Hotfix_2000-12-08/Hotfix_2000-12-08. tgz
Zope Zope 2.2.3
-
Zope Zope 2.2.4 Hotfix_2000-12-08.tgz
This is for the Zope software package released 2.2.0 thru 2.2.4.
http://www.zope.org/Products/Zope/Hotfix_2000-12-08/Hotfix_2000-12-08. tgz
Zope Zope 2.2.4
-
Debian 2.2 alpha zope_2.1.6-5.4_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/zope _2.1.6-5.4_alpha.deb -
Debian 2.2 arm zope_2.1.6-5.4_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/zope_2 .1.6-5.4_arm.deb -
Debian 2.2 i386 zope_2.1.6-5.4_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/zope_ 2.1.6-5.4_i386.deb -
Debian 2.2 m68k zope_2.1.6-5.4_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/zope_ 2.1.6-5.4_m68k.deb -
Debian 2.2 ppc zope_2.1.6-5.4_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/zo pe_2.1.6-5.4_powerpc.deb -
Debian 2.2 sparc zope_2.1.6-5.4_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/zope _2.1.6-5.4_sparc.deb -
MandrakeSoft 7.1 i386 Zope-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.1/RPMS/Zope-2.2 .4-1.2mdk.i586.rpm -
MandrakeSoft 7.1 i386 Zope-components-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.1/RPMS/Zope-com ponents-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.1 i386 Zope-core-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.1/RPMS/Zope-cor e-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.1 i386 Zope-pcgi-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.1/RPMS/Zope-pcg i-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.1 i386 Zope-services-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.1/RPMS/Zope-ser vices-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.1 i386 Zope-zpublisher-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.1/RPMS/Zope-zpu blisher-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.1 i386 Zope-zserver-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.1/RPMS/Zope-zse rver-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.1 i386 Zope-ztemplates-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.1/RPMS/Zope-zte mplates-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 Zope-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.2/RPMS/Zope-2.2 .4-1.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 Zope-components-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.2/RPMS/Zope-com ponents-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 Zope-core-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.2/RPMS/Zope-cor e-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 Zope-pcgi-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.2/RPMS/Zope-pcg i-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 Zope-services-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.2/RPMS/Zope-ser vices-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 Zope-zpublisher-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.2/RPMS/Zope-zpu blisher-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 Zope-zserver-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.2/RPMS/Zope-zse rver-2.2.4-1.2mdk.i586.rpm -
MandrakeSoft 7.2 i386 Zope-ztemplates-2.2.4-1.2mdk.i586.rpm
http://sunsite.ualberta.ca/pub/Mirror/Linux/mandrake/7.2/RPMS/Zope-zte mplates-2.2.4-1.2mdk.i586.rpm -
Red Hat Inc. 6.1 noarch Zope-Hotfix-DTML-2000_12_18-1.noarch.rpm
ftp://updates.redhat.com/powertools/6.2/noarch/Zope-Hotfix-DTML-2000_1 2_18-1.noarch.rpm -
Red Hat Inc. 6.1 source Zope-Hotfix-DTML-2000_12_18-1.src.rpm
ftp://updates.redhat.com/powertools/6.2/SRPMS/Zope-Hotfix-DTML-2000_12 _18-1.src.rpm -
Red Hat Inc. 6.2 noarch Zope-Hotfix-DTML-2000_12_18-1.noarch.rpm
ftp://updates.redhat.com/powertools/6.2/noarch/Zope-Hotfix-DTML-2000_1 2_18-1.noarch.rpm -
Red Hat Inc. 6.2 source Zope-Hotfix-DTML-2000_12_18-1.src.rpm
ftp://updates.redhat.com/powertools/6.2/SRPMS/Zope-Hotfix-DTML-2000_12 _18-1.src.rpm -
Red Hat Inc. 7.0 noarch Zope-Hotfix-DTML-2000_12_18-1.noarch.rpm
ftp://updates.redhat.com/powertools/7.0/noarch/Zope-Hotfix-DTML-2000_1 2_18-1.noarch.rpm -
Red Hat Inc. 7.0 source Zope-Hotfix-DTML-2000_12_18-1.src.rpm
ftp://updates.redhat.com/powertools/7.0/SRPMS/Zope-Hotfix-DTML-2000_12 _18-1.src.rpm -
Zope Zope 2.2.4 Hotfix_2000-12-08.tgz
This is for the Zope software package released 2.2.0 thru 2.2.4.
http://www.zope.org/Products/Zope/Hotfix_2000-12-08/Hotfix_2000-12-08. tgz
References
Zope DTML Editing Vulnerability
References:
References:
- [Zope-Annce] SECURITY alert and hotfix release (Zope)
- Welcome to Zope.org (Zope)
- Zope README (Zope)