[Zope-Annce] ATTN: Zope Security Alert

Chris McDonough chrism@zope.com
Sat, 4 Aug 2001 11:28:51 -0400


A new Zope hotfix has been issued which addresses an important security
issue that affects Zope version 2.3.3, all Zope 2.4.0 alpha and beta
releases, as well as the final release of Zope 2.4.0.

We *highly* recommend that any Zope site running Zope 2.3.3, Zope
2.4.0 final or any alpha or beta version of 2.4.0 have this hotfix
product installed to mitigate the issue. Zope 2.4.1 will contain a
fix for the issue, at which time the hotfix can be removed.

Zope versions prior to 2.3.3 are not affected by this issue.

Thanks to Ron Bickers for providing a reproducible test case

For more information, see:

http://www.zope.org/Products/Zope/Hotfix_2001-08-04/README.txt
http://www.zope.org/Products/Zope/Hotfix_2001-08-04/Hotfix_2001_08_04.tgz

----------
Chris McDonough                           Zope Corporation
http://www.zope.org                    http://www.zope.com

""" Killing hundreds of birds with thousands of stones """