Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 389251 - net-zope/zope-2.13.x unspecified error allows arbitrary code execution (CVE-2011-3587)
Summary: net-zope/zope-2.13.x unspecified error allows arbitrary code execution (CVE-2...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://zope2.zope.org/news/security-v...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-11-01 22:42 UTC by Michael Harrison
Modified: 2011-11-02 07:28 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Harrison 2011-11-01 22:42:08 UTC
A vulnerability has been reported in Zope, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an unspecified error and can be exploited to execute arbitrary commands by sending specially crafted requests to the server.

The vulnerability is reported in versions 2.12.x and 2.13.x
Comment 1 Arfrever Frehtes Taifersar Arahesis 2011-11-01 23:06:05 UTC
net-zope/zope-2.12.20 and net-zope/zope-2.13.10 contain fix for this vulnerability and they were already added on 2011-10-04.