First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 141578
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 141578 depends on: Show dependency tree
Show dependency graph
Bug 141578 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-24 06:27 0000
Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not
disable the "raw" command when providing untrusted users with restructured text
(reStructuredText) functionality from docutils, which allows local users to
read arbitrary files.

------- Comment #1 From Sune Kloppenborg Jeppesen 2006-07-24 06:28:35 0000 -------
net-zope please advise and patch as necessary.

------- Comment #2 From Radoslaw Stachowiak 2006-07-24 16:10:51 0000 -------
Unfortunately I'll be able to provide patch/ebuild no sooner than Jul 31
(vacations). We ll need to patch it.

------- Comment #3 From Thierry Carrez (RETIRED) 2006-08-12 05:26:27 0000 -------
Radoslaw : back from your vacations ?

------- Comment #4 From Radoslaw Stachowiak 2006-08-20 12:37:48 0000 -------
Released 2.8.8 and 2.9.4 which contain fix for the bug.
I think we should stable 2.8.8 and pmask 2.7

------- Comment #5 From Sune Kloppenborg Jeppesen 2006-08-20 13:14:47 0000 -------
Thx Radoslaw.

Arches please test and mark stable 2.8.8 as per comment #4.

------- Comment #6 From Radoslaw Stachowiak 2006-08-21 13:20:46 0000 -------
due to today discovered http://www.zope.org/Products/Zope/Hotfix-2006-08-21/
we should probably stop before ill be able to fix this altogether (max till
saturday).

------- Comment #7 From Sune Kloppenborg Jeppesen 2006-08-22 22:13:07 0000 -------
Back to ebuild status.

------- Comment #8 From Radoslaw Stachowiak 2006-08-27 10:01:09 0000 -------
Fixed 2.7.9 and 2.8.8.

There is no need to mask 2.7.8 now as I previously stated (because i fixed it
this time), but there is need to make 2.7.9 stable.

In summary, what is needed:
1) mark as stable zope-2.7.9 (new ebuild)
2) mark as stable zope-2.8.8 (changed ebuild, I decided against version bump
because 2.8.8 was not marked as stable in portage yet)
3) issue glsa, versions NOT affected are:
zope-2.7.9 (the only stable version before the situation)
zope-2.8.8 (only after re-emerge!!!)
zope-2.9.4

Do not hesitate to ask me if sth is not clear.

------- Comment #9 From Sune Kloppenborg Jeppesen 2006-08-29 11:44:48 0000 -------
Thx Radoslaw.

Arches please test and mark stable.

------- Comment #10 From Joshua Jackson 2006-08-29 21:20:50 0000 -------
I hate zope and plone but they are done on x86 :(

------- Comment #11 From Gustavo Zacarias (RETIRED) 2006-08-30 10:20:41 0000 -------
sparc stable.

------- Comment #12 From Tobias Scherbaum 2006-09-01 10:20:50 0000 -------
ppc stable

------- Comment #13 From Simon Stelling (RETIRED) 2006-09-02 05:18:34 0000 -------
amd64 stable

------- Comment #14 From Thomas Cort (RETIRED) 2006-09-03 08:43:03 0000 -------
alpha stable.

Also marked 2.8.8 stable on amd64.

------- Comment #15 From Sune Kloppenborg Jeppesen 2006-09-03 09:48:21 0000 -------
This one is ready for GLSA decision. I tend to vote NO.

------- Comment #16 From Radoslaw Stachowiak 2006-09-03 11:05:00 0000 -------
If I should vote (not sure?) i think we should release GLSA. this is pretty
serious bug (remote one) - in fact two advisories were issued, and it's happend
after long time zope being considered secure app server. 

------- Comment #17 From Wolf Giesen (RETIRED) 2006-09-05 06:17:28 0000 -------
I vote yes.

------- Comment #18 From Raphael Marichez 2006-09-05 11:24:38 0000 -------
i vote no. This is not a critical issue. It can not corrupt a server nor
execute any kind of script.

------- Comment #19 From Thierry Carrez (RETIRED) 2006-09-05 12:51:42 0000 -------
I tend to vote no. It's not that often that you provide restructured text
functions to untrusted users ?

------- Comment #20 From Sune Kloppenborg Jeppesen 2006-09-05 21:09:51 0000 -------
Current voting status:

2 NO (

------- Comment #21 From Sune Kloppenborg Jeppesen 2006-09-05 21:09:51 0000 -------
Current voting status:

2 NO (½+½+1)
1 YES (+1 from net-zope)

So unless I get some YES votes today I'll close this bug with NO GLSA.

------- Comment #22 From Raphael Marichez 2006-09-07 07:05:55 0000 -------
closing with noglsa, feel free to reopen if blabla (i should bind a
shortcut-key for this)

First Last Prev Next    No search results available      Search page      Enter new bug