PT-2001-1064 · Zope+1 · Zope+1
Publicado
2001-05-28
·
Atualizado
2017-10-10
·
CVE-2001-1227
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
man versions prior to 1.5i2
Zope versions prior to 2.2.4
Description
The issue concerns multiple vulnerabilities in the man package of Red Hat Linux and Zope, which can be exploited remotely to compromise the confidentiality, integrity, and availability of protected information. In Zope, partially trusted users can bypass security controls for certain methods by accessing them through the
fmt attribute of dtml-var tags.Recommendations
For man package versions prior to 1.5i2, update to version 1.5i2 or later to resolve the issue.
For Zope versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
dtml-var tags and the fmt attribute in Zope until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zope
Man