what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

rhsa.2000-052-02.zope

rhsa.2000-052-02.zope
Posted Aug 13, 2000
Site redhat.com

Red Hat Security Advisory - Vulnerabilities exist with all Zope-2.0 releases - This HotFix corrects issues in the getRoles method of user objects contained in the default UserFolder implementation. Users with the ability to edit DTML could arrange to give themselves extra roles for the duration of a single request by mutating the roles list as a part of the request processing.

tags | vulnerability
systems | linux, redhat
SHA-256 | 3aae58fa2ce77f6e29e2937cd2bf1a04b0f4bc3336e8c2895523e8de5692adca

rhsa.2000-052-02.zope

Change Mirror Download
---------------------------------------------------------------------
Red Hat, Inc. Security Advisory

Synopsis: Zope update
Advisory ID: RHSA-2000:052-02
Issue date: 2000-08-11
Updated on: 2000-08-11
Product: Red Hat Powertools
Keywords: Zope
Cross references: N/A
---------------------------------------------------------------------

1. Topic:

Vulnerabilities exist with all Zope-2.0 releases.

2. Relevant releases/architectures:

Red Hat Powertools 6.1 - noarch
Red Hat Powertools 6.2 - noarch

3. Problem description:

This HotFix corrects issues in the getRoles method of user objects
contained in the default UserFolder implementation. Users with the ability
to edit DTML could arrange to give themselves extra roles for the duration
of a single request by mutating the roles list as a part of the request
processing.

4. Solution:

Users of Red Hat Powertools 6.1 who have not upgraded Zope to the version
of Zope released in Red Hat Powertools 6.2 (2.1.2-5) need to do so prior to
installing this Zope update. The Zope packages from 6.2 are located at:=20

ftp://ftp.redhat.com/pub/redhat/powertools/6.2/

After you have upgraded to Zope-2.1.2-5 install the Zope-Hotfix package. To
install the update, use this command:

rpm -Uvh Zope-Hotfix-DTML-08_09_2000-1.noarch.rpm

Once the Zope-Hotfix package is installed, restart Zope.

5. Bug IDs fixed (https://bugzilla.redhat.com/bugzilla for more info):

N/A

6. RPMs required:

Red Hat Powertools 6.2:

noarch:
ftp://updates.redhat.com/powertools/6.2/noarch/Zope-Hotfix-DTML-08_09_2000-=
1.noarch.rpm

sources:
ftp://updates.redhat.com/powertools/6.2/SRPMS/Zope-Hotfix-DTML-08_09_2000-1=
.src.rpm

7. Verification:

MD5 sum Package Name
--------------------------------------------------------------------------
d008c975cec06c552172659ffb14a3a1 6.2/SRPMS/Zope-Hotfix-DTML-08_09_2000-1.s=
rc.rpm
61e9f5fed71cbb784f2e1352cb98fb1a 6.2/noarch/Zope-Hotfix-DTML-08_09_2000-1.=
noarch.rpm

These packages are GPG signed by Red Hat, Inc. for security. Our key
is available at:
https://www.redhat.com/corp/contact.html

You can verify each package with the following command:
rpm --checksig <filename>

If you only wish to verify that each package has not been corrupted or
tampered with, examine only the md5sum with the following command:
rpm --checksig --nogpg <filename>

8. References:

https://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert


Copyright(c) 2000 Red Hat, Inc.

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close