RedHat: UPDATE: 'Zope' vulnerability
Summary
Summary
The issue involves incorrect protection of a data updating method on Imageand File objects. Because the method was not correctly protected, it waspossible for users with DTML editing privileges to update the raw data ofaprivileges File or Image object via DTML, though they did not have editingon the objects themselves.
Solution
For each RPM for your particular architecture, run:
rpm -Fvh [filename]
where filename is the name of the RPM.
Please make sure that you have updated you Zope packages to version 2.2.4
prior to applying this Hotfix. After you have installed this Hotfix,
restart Zope.
5. Bug IDs fixed ( for more info):
6. RPMs required:
Red Hat Powertools 6.1 and 6.2:
SRPMS:
noarch:
Red Hat Powertools 7.0:
SRPMS:
noarch:
7. Verification:
MD5 sum Package Name
8eef0f0590bce92e4ea7a65ad25b3d67 6.2/noarch/Zope-Hotfix-DTML-2000_12_18-1.noarch.rpm
bb611337425fe1097a5bf8d55f4c6ae7 7.0/noarch/Zope-Hotfix-DTML-2000_12_18-1.noarch.rpm
44092ed99f67a7906a4347ae30110ee4 6.2/SRPMS/Zope-Hotfix-DTML-2000_12_18-1.src.rpm
f98b08150235d97ac758102d5c203ec2 7.0/SRPMS/Zope-Hotfix-DTML-2000_12_18-1.src.rpm
These packages are GPG signed by Red Hat, Inc. for security. Our key
is available at:
You can verify each package with the following command:
rpm --checksig
If you only wish to verify that each package has not been corrupted or
tampered with, examine only the md5sum with the following command:
rpm --checksig --nogpg
References
Copyright(c) 2000 Red Hat, Inc. `
Package List
Topic
Topic
A new Zope Hotfix package is available.
Relevant Releases Architectures
Red Hat Powertools 6.1 and 6.2 - noarch
Red Hat Powertools 7.0 - noarch
Bugs Fixed