Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 149602 - net-zope/{passwordresettool,plone): Plone 2.5 password reset tool vulnerability
Summary: net-zope/{passwordresettool,plone): Plone 2.5 password reset tool vulnerability
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://plone.org/news/plone-security-...
Whiteboard: ~3 [noglsa] vorlon
Keywords:
Depends on:
Blocks:
 
Reported: 2006-09-30 03:39 UTC by Janne Pikkarainen
Modified: 2006-10-01 00:43 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Janne Pikkarainen 2006-09-30 03:39:38 UTC
Plone 2.5 is vulnerable to password reset bug. Plone administrators are encouraged to patch as soon as possible.

Only Plone 2.5 and Plone 2.5.1-rc's are affected, unless Password Tool v0.4.0 is separately installed to older Plone versions of Plone.
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2006-09-30 13:37:10 UTC
net-zope, please provide updated ebuilds for the vulnerable packages

could you also comment on the affected ebuilds?

is it just:
net-zope/plone-2.5 and 2.5.1_rc1
net-zope/passwordresettool

those are all marked ~arch if i am not mistaken, aren't they?
Comment 2 Radoslaw Stachowiak (RETIRED) gentoo-dev 2006-09-30 14:05:48 UTC
Net-zope reports on duty.

currently 2.5 and 2.5.1rc1 are only ~x86 so no direct threat.
I will however in comming minutes:
* remove rc1 from tree
* commit 2.5.1 (~86)

I plan to leave intact 2.5 under ~x86, and need to check passwordresettool. Probably prt will be bumped too.
Comment 3 Radoslaw Stachowiak (RETIRED) gentoo-dev 2006-09-30 14:25:38 UTC
ok, done:
plone-2.5.1 commited (~x86)
plone-2.5.1-rc1 removed from tree

passwordresettool bumped.

no glsa needed IMO.

P.S.
and someone complained on gentoo-dev about maintainers being lazy on security bugs ;)
Comment 4 Matthias Geerdsen (RETIRED) gentoo-dev 2006-09-30 14:37:55 UTC
great :)
now this was a quick bug...

closing without glsa as all packages are marked ~arch
Comment 5 Janne Pikkarainen 2006-10-01 00:43:30 UTC
Wow. Dudes, you rock! :-) This was a very fast one. 

Thank you very much and keep up the good work!