Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 373989 (CVE-2011-2528)

Summary: net-zope/zope, net-zope/plone: Unspecified Serious Vulnerability (CVE-2011-2528)
Product: Gentoo Security Reporter: Tim Sammut (RETIRED) <underling>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED OBSOLETE    
Severity: major CC: net-zope+disabled
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://plone.org/products/plone/security/advisories/20110622
Whiteboard: B1 [noglsa]
Package list:
Runtime testing required: ---

Description Tim Sammut (RETIRED) gentoo-dev 2011-07-04 05:40:37 UTC
From $URL:

A highly serious vulnerability in Zope that allows unauthorised access

The fix  was released at 15:00 UTC on Tuesday 28th June, 2011.

Full installation instructions.
Who should apply the patch

    * Plone 4.x users must apply this patch or update to Zope2 2.12.19 (Plone 4.0) or 2.13.8 (Plone 4.1).
    * Zope 2.12/2.13 users must apply this patch or update to Zope2 2.12.19 or 2.13.8.
    * Plone 3.x users: the vulnerability was inadvertently backported by the previous hotfix http://plone.org/products/plone-hotfix/releases/CVE-2011-0720 (PloneHotfix20110720). Plone 3.x users should install both PloneHotfix20110720 and this hotfix to make sure that they are protected against both sets of vulnerabilities.
    * Zope 2.10/2.11 users who are not using Plone: Zope 2.10 and 2.11 users who have not installed PloneHotfix20110720 are not affected by this vulnerability, and should not apply the patch. You should, however, make sure that you are running either Zope 2.10.13 or Zope 2.11.8  and PluggableAuthService 1.5.5, 1.6.5 or 1.7.5 which include fixes for the vulnerabilities in CVE-2011-0720. Please make sure that you have not installed PloneHotfix20110720; remove it if you have.

Other versions are not affected. Plone 2.5 and Zope 2.8/2.9 are unaffected; you should not install this hotifx on those sites.
Comment 1 Arfrever Frehtes Taifersar Arahesis 2011-10-02 16:06:14 UTC
Vulnerable versions are masked.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-10-02 23:48:21 UTC
GLSA request filed.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2011-10-07 22:39:34 UTC
CVE-2011-2528 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2528):
  Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x
  before 2.13.8, as used in Plone 4.x and other products, and (2)
  PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via
  unspecified vectors, related to a "highly serious vulnerability." NOTE: this
  vulnerability exists because of an incorrect fix for CVE-2011-0720.
Comment 4 Tobias Heinlein (RETIRED) gentoo-dev 2014-02-09 13:07:28 UTC
Closing old stuff.