Mandrake Linux Security Advisory : Zope (MDKSA-2001:025)

low Nessus Plugin ID 61899

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

A new Hotfix for Zope has been released that fixes a very important security issue that affects all versions of Zope prior to and including 2.3.1b1. Users can use through-the-web scripting capabilities on a Zope site to view and assign class attributes to ZClasses, possibly allowing them to make inappropriate changes to ZClass instances. As well, perceived security problems with the ObjectManager, PropertyManager and PropertySheet classes have been fixed as well. It is highly recommended that all Linux-Mandrake users using Zope upgrade to these new packages immediately.

Solution

Update the affected packages.

Plugin Details

Severity: Low

ID: 61899

File Name: mandrake_MDKSA-2001-025.nasl

Version: 1.6

Type: local

Published: 9/6/2012

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Low

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:zope, p-cpe:/a:mandriva:linux:zope-components, p-cpe:/a:mandriva:linux:zope-core, p-cpe:/a:mandriva:linux:zope-pcgi, p-cpe:/a:mandriva:linux:zope-services, p-cpe:/a:mandriva:linux:zope-zpublisher, p-cpe:/a:mandriva:linux:zope-zserver, p-cpe:/a:mandriva:linux:zope-ztemplates, cpe:/o:mandrakesoft:mandrake_linux:7.1, cpe:/o:mandrakesoft:mandrake_linux:7.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2/26/2001

Reference Information

CVE: CVE-2001-0569

MDKSA: 2001:025