<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>153901</bug_id>
          
          <creation_ts>2006-11-02 23:56 0000</creation_ts>
          <short_desc>net-zope/plone 2.5 and 2.5.1 security hotfix 20061031 released (CVE-2006-4249)</short_desc>
          <delta_ts>2007-01-12 22:32:02 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://plone.org/products/plone-hotfix/releases/20061031</bug_file_loc>
          <status_whiteboard>~4? [noglsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaba@mikrobitti.fi</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>net-zope@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaba@mikrobitti.fi</who>
            <bug_when>2006-11-02 23:56:11 0000</bug_when>
            <thetext>Since this is couple of days old and haven&apos;t seen this here yet mentioned at all, I thought I could as well inform you. 

Plone versions 2.5 and 2.5.1 has a potential vulnerability that allows user to masquerade as a group. More information &amp; patch available at the URL I put above.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2006-11-06 03:57:49 0000</bug_when>
            <thetext>net-zope, pls provide an updated ebuild

btw, the affected version is in ~arch, so no GLSA will be needed
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2006-12-19 11:05:46 0000</bug_when>
            <thetext>Deeply sorry for the delay (I&apos;m the only active deveolper for net-zope/*).
This one will be fixed around Dec 24th together with some version bumps.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-12-22 00:48:25 0000</bug_when>
            <thetext>Thx Radek. Please comment again on this bug when you commit the updated ebuild.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2006-12-28 17:37:02 0000</bug_when>
            <thetext>Both plone-2.5 and plone-2.5.1 fixed to contain this hotfix upon installation.
No version bump.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-12-29 01:42:03 0000</bug_when>
            <thetext>Thx Radoslaw.

Normally we encourage a version bump so emerge world users will pick up the update.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2007-01-01 07:52:50 0000</bug_when>
            <thetext>Update won&apos;t be picked, beacuse zope product are installed in two phase process, while second phase (zprod-manager) is strictly manual. simply emerging app (plone here) will just result with new plone source being on machine, but not one which is currently used in zope instance.

one can argue, that even in such case, bump is suggested, because subsequent plone installations can be fixed, but net-zope policy didnt do it till recently.

So, knowing this, is Your recommendation still to revbump it? if yes, i&apos;ll do it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-01-06 12:51:20 0000</bug_when>
            <thetext>I would prefer a bump with a post install message telling the user what to do.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>radek@gentoo.org</who>
            <bug_when>2007-01-09 22:55:39 0000</bug_when>
            <thetext>plone-2.5.1-r1.ebuild commited.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-01-12 22:32:02 0000</bug_when>
            <thetext>the only stable ebuild (2.0.4 and 2.0.5) are not vulnerable --&gt; closing. Feel free to reopen if you disagree</thetext>
          </long_desc>
      
    </bug>

</bugzilla>