[Zope] Zope 2.1.5/6/7 & ZSQLMethods problem

Ron Bickers rbickers@logicetc.com
Fri, 16 Jun 2000 01:03:56 -0400


> > I assume based on the change log that this is the only fix in 2.1.7,
> > correct?
>
> Yes, this is the only fix (that I can verify, Brian has the final say(!)).
>
> Also, again as far as I can verify, the supplied patch can be
> applied to all
> Zope version 2.0.0b5 and up without problems. If you look at the
> patch you'll
> see it involves the adding of two lines, thus very easy to apply
> by hand if
> need be.

That will get me the fix for 2.1.7, but what about the 2 security fixes in
2.1.5 (which I believe is what broke it in the first place) and the numerous
other bug fixes?

I know I'm not the only one running 2.1.4 because of misbehaving ZSQLMethods
in 2.1.5/6/7, and wondering when my site is going to be exploited because of
the security issues.  Broken or vulnerable seem to be my two choices.  Not a
very good selection.

_______________________

Ron Bickers
Logic Etc, Inc.
rbickers@logicetc.com