<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>109087</bug_id>
          
          <creation_ts>2005-10-12 22:14 0000</creation_ts>
          <short_desc>net-zope/zope: docutils-related security issue</short_desc>
          <delta_ts>2005-10-25 04:49:14 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.zope.org/</bug_file_loc>
          <status_whiteboard>B2? [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>net-zope@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-10-12 22:14:32 0000</bug_when>
            <thetext>Hotfix 2005-10-09 Alert 
This hotfix addresses an important security issue that affects users of Zope 
versions 2.6 or higher. 
This hotfix resolves a security issue with docutils. 
Affected are possibly all Zope instances that expose RestructuredText 
functionalies to untrusted users through the web.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-13 01:21:44 0000</bug_when>
            <thetext>net-zope herd, please apply hotfix</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-16 03:07:30 0000</bug_when>
            <thetext>Also in :
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=334054

zope team, please bump. If you find what is the impact of the flaw please comment.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2005-10-16 03:28:32 0000</bug_when>
            <thetext>will do today.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2005-10-17 15:06:18 0000</bug_when>
            <thetext>fixed in portage with two new versions 2.7.8 and 2.8.2 which contains fixes for
the vulnabirity.

2.6.x is not supported, we have no information if this can be even patched.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-10-17 22:53:16 0000</bug_when>
            <thetext>Thx Radoslaw. 
 
Arches please test and mark stable. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-10-18 06:43:13 0000</bug_when>
            <thetext>Hmm which version? 2.7.8 or 2.8.2?
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-18 06:50:34 0000</bug_when>
            <thetext>Latest stable was 2.7.7, so 2.7.8 should probably be the stable target.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-10-18 07:26:26 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-10-18 11:08:44 0000</bug_when>
            <thetext>ppc done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-10-18 15:24:51 0000</bug_when>
            <thetext>Alpha stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-19 02:06:29 0000</bug_when>
            <thetext>Not sure what this is about. Can&apos;t find anything clear in the Changelog... Maybe
that :

&lt;&lt;disabled &quot;.. include&quot; directive for all the ZReST product and the
reStructuredText package&gt;&gt;

Looks like a file inclusion issue... maybe local file disclosure ?

Radoslaw, any info ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2005-10-19 04:50:05 0000</bug_when>
            <thetext>i think we can provide general information, about file inclusion, but give a
clear info that this allows to break security of the zope to untrusted users
through the web.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2005-10-19 04:52:06 0000</bug_when>
            <thetext>I also need to release 2.8.3 tonight, because there were some problems on
zope2.8.2 release (http://www.zope.org/Products/Zope/2.8.3/CHANGES.txt)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2005-10-19 13:45:54 0000</bug_when>
            <thetext>release 2.8.3
i suggest that advisory mention also that for 2.8.x branch upgrade to the 2.8.3
should be done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2005-10-19 22:51:52 0000</bug_when>
            <thetext>stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-20 08:28:22 0000</bug_when>
            <thetext>Radoslaw: removing/masking the 2.8.2 version is the best way to achieve the
result from comment #14. 

Technically &gt;=2.8.2 is fixed (security-wise) so that&apos;s probably what we&apos;ll put
in the GLSA. They will pick up 2.8.3 naturally if 2.8.2 is missing...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-21 08:18:58 0000</bug_when>
            <thetext>amd64 still missing, should mark 2.7.8 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-10-23 04:48:08 0000</bug_when>
            <thetext>amd64 stable, sorry for the delay</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-10-25 04:49:14 0000</bug_when>
            <thetext>GLSA 200510-20</thetext>
          </long_desc>
      
    </bug>

</bugzilla>