[Zope-Annce] SECURITY alert and hotfix release...

Brian Lloyd brian@digicool.com
Fri, 23 Feb 2001 17:33:23 -0500


Hello All,

  Casey Duncan uncovered a potential security issue today that
  necessitated a hotfix release.

  This hotfix addresses an important security issue that affects Zope
  versions up to and including Zope 2.3.1 b1.

  The issue is related to ZClasses in that a user with through-the-web
  scripting capabilities on a Zope site can view and assign class attributes
  to ZClasses, possibly allowing them to make inappropriate changes to
ZClass
  instances.

  This patch also fixes problems in the ObjectManager, PropertyManager, and
  PropertySheet classes related to mutability of method return values which
  could be perceived as a security problem.

  We *highly* recommend that any Zope site running versions of
  Zope up to and including 2.3.1 b1 have this hotfix product installed
  to mitigate these issues if the site is accessible by untrusted users
  who have through-the-web scripting privileges.

    - http://www.zope.org/Products/Zope/Hotfix_2001-02-23/README.txt

    -
http://www.zope.org/Products/Zope/Hotfix_2001-02-23/Hotfix_2001-02-23.tgz



Brian Lloyd        brian@digicool.com
Software Engineer  540.371.6909
Digital Creations  http://www.digicool.com