Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 129705 - net-zope/plone: manipulation of user portraits by anonymous users (CVE-2006-1711)
Summary: net-zope/plone: manipulation of user portraits by anonymous users (CVE-2006-1...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor
Assignee: Gentoo Security
URL: http://dev.plone.org/plone/ticket/5432
Whiteboard: B4 [noglsa] Falco
Keywords:
Depends on:
Blocks:
 
Reported: 2006-04-12 08:44 UTC by Raphael Marichez (Falco) (RETIRED)
Modified: 2006-04-17 09:42 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-04-12 08:44:31 UTC
The Plone content management system lacks security declarations for three internal classes.
This allows manipulation of user portraits by unprivileged users.

The changeMemberPortrait and deletePersonalPortrait lack security declarations, enabling any anonymous internet user to change and delete portraits on Plone sites at will.

Our versions 2.0.4 and 2.0.5 and 2.0.5-r1 are not patched

See also DSA 1032-1 (2006-04-12)
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2006-04-15 05:34:47 UTC
Zope herd please bump with patch from URL
Comment 2 Radoslaw Stachowiak (RETIRED) gentoo-dev 2006-04-16 04:31:00 UTC
plone-2.0.5-r2 is in portage and patched. Not marked stable though.
Please test and proceeed with stable and glsa.
Comment 3 Stefan Cornelius (RETIRED) gentoo-dev 2006-04-16 05:13:17 UTC
x86 and ppc please test and mark plone-2.0.5-r2 stable, thx
Comment 4 Tobias Scherbaum (RETIRED) gentoo-dev 2006-04-16 14:51:26 UTC
Patch doesn't apply.

 * Applying plone-2.0.5-portrait_security.patch ...

 * Failed Patch: plone-2.0.5-portrait_security.patch !
 *  ( /home/tobias/cvs/gentoo-x86/net-zope/plone/files/plone-2.0.5-portrait_security.patch )
 *
 * Include in your bugreport the contents of:
 *
 *   /var/tmp/portage/plone-2.0.5-r2/temp/plone-2.0.5-portrait_security.patch-6632.out
Comment 5 Stefan Cornelius (RETIRED) gentoo-dev 2006-04-16 14:54:46 UTC
net-zope please fix the ebuild, thanks
Comment 6 Radoslaw Stachowiak (RETIRED) gentoo-dev 2006-04-16 18:03:38 UTC
Strange, just did emerge sync and tested in on data received from rsync.gentoo.org and it works:
>>> Unpacking PloneBase-2.0.5.tar.gz to /var/tmp/portage/plone-2.0.5-r2/work
 * Applying plone-2.0.5-portrait_security.patch ...                                                      [ ok ]
>>> Source unpacked.

Can anyone help me here?
Comment 7 Radoslaw Stachowiak (RETIRED) gentoo-dev 2006-04-17 06:24:01 UTC
OK, fixed. Looks like that my patch accepts wide range of patch files, while standrad one not. I regenerated and commited fixed patch file.

Please proceed. Sorry for the trobules caused.
Comment 8 Stefan Cornelius (RETIRED) gentoo-dev 2006-04-17 06:29:05 UTC
No problem, thank you radek. Arches, you know what to do :)
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2006-04-17 07:21:07 UTC
ppc stable
Comment 10 Mark Loeser (RETIRED) gentoo-dev 2006-04-17 08:46:08 UTC
x86 done
Comment 11 Stefan Cornelius (RETIRED) gentoo-dev 2006-04-17 08:53:24 UTC
ready for glsa vote, i tend to a NO here.
Comment 12 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-04-17 08:56:18 UTC
thanks arches,

not a critical element, only affects plone itself.

I tend to vote no, but unsure.
Comment 13 Thierry Carrez (RETIRED) gentoo-dev 2006-04-17 09:42:38 UTC
Voting NO and closing.