漏洞信息详情
Zope代理人角色提高对象访问漏洞
- CNNVD编号:CNNVD-200204-032
- 危害等级: 高危
- CVE编号:
CVE-2002-0170
- 漏洞类型:
设计错误
- 发布时间:
2002-04-22
- 威胁类型:
远程
- 更新时间:
2005-05-02
- 厂 商:
zope - 漏洞来源:
Published by Matth… -
漏洞简介
Zope 2.2.0到2.5.1版本不能正确查证带代理人角色的访问对象。一些用户可以违反预期的配置访问文档。
漏洞公告
Fixes available:
Zope Zope 2.2 .0
-
Zope Hotfix_2002-03-01.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-03-01/Hotfix_2002-03-01.
tgz
Zope Zope 2.2.1
-
Zope Hotfix_2002-03-01.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-03-01/Hotfix_2002-03-01.
tgz
Zope Zope 2.2.2
-
Zope Hotfix_2002-03-01.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-03-01/Hotfix_2002-03-01.
tgz
Zope Zope 2.2.3
-
Zope Hotfix_2002-03-01.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-03-01/Hotfix_2002-03-01.
tgz
Zope Zope 2.2.4
-
Zope Hotfix_2002-03-01.tgz
http://www.zope.org/Products/Zope/Hotfix_2002-03-01/Hotfix_2002-03-01.
tgz
Zope Zope 2.2.5
-
Red Hat Zope-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/Zope-2.2.5-17.alpha.r
pm -
Red Hat Zope-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/Zope-2.2.5-17.alpha.r
pm -
Red Hat Zope-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/Zope-2.2.5-17.i386.rpm
-
Red Hat Zope-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/Zope-2.2.5-17.i386.rpm
-
Red Hat Zope-components-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/Zope-components-2.2.5
-17.alpha.rpm -
Red Hat Zope-components-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/Zope-components-2.2.5
-17.alpha.rpm -
Red Hat Zope-components-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/Zope-components-2.2.5-
17.i386.rpm -
Red Hat Zope-components-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/Zope-components-2.2.5-
17.i386.rpm -
Red Hat Zope-core-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/Zope-core-2.2.5-17.al
pha.rpm -
Red Hat Zope-core-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/Zope-core-2.2.5-17.al
pha.rpm -
Red Hat Zope-core-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/Zope-core-2.2.5-17.i38
6.rpm -
Red Hat Zope-core-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/Zope-core-2.2.5-17.i38
6.rpm -
Red Hat Zope-pcgi-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/Zope-pcgi-2.2.5-17.al
pha.rpm -
Red Hat Zope-pcgi-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/Zope-pcgi-2.2.5-17.al
pha.rpm -
Red Hat Zope-pcgi-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/Zope-pcgi-2.2.5-17.i38
6.rpm -
Red Hat Zope-pcgi-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/Zope-pcgi-2.2.5-17.i38
6.rpm -
Red Hat Zope-services-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/Zope-services-2.2.5-1
7.alpha.rpm -
Red Hat Zope-services-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/Zope-services-2.2.5-1
7.alpha.rpm -
Red Hat Zope-services-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/Zope-services-2.2.5-17
.i386.rpm -
Red Hat Zope-services-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/Zope-services-2.2.5-17
.i386.rpm -
Red Hat Zope-zpublisher-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/Zope-zpublisher-2.2.5
-17.alpha.rpm -
Red Hat Zope-zpublisher-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/Zope-zpublisher-2.2.5
-17.alpha.rpm -
Red Hat Zope-zpublisher-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/Zope-zpublisher-2.2.5-
17.i386.rpm -
Red Hat Zope-zpublisher-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/Zope-zpublisher-2.2.5-
17.i386.rpm -
Red Hat Zope-zserver-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.0/en/powertools/alpha/Zope-zserver-2.2.5-17
.alpha.rpm -
Red Hat Zope-zserver-2.2.5-17.alpha.rpm
ftp://updates.redhat.com/7.1/en/powertools/alpha/Zope-zserver-2.2.5-17
.alpha.rpm -
Red Hat Zope-zserver-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.0/en/powertools/i386/Zope-zserver-2.2.5-17.
i386.rpm -
Red Hat Zope-zserver-2.2.5-17.i386.rpm
ftp://updates.redhat.com/7.1/en/powertools/i386/Zope-zserver-2.2.5-17.
i386.rpm -
Red Hat Zope-ztemplates-2.2.5-17.alpha.rpm
参考网址
来源: www.zope.org
链接:http://www.zope.org/Products/Zope/hotfixes/来源: BID
名称: 4229
链接:http://www.securityfocus.com/bid/4229来源: REDHAT
名称: RHSA-2002:060
链接:http://www.redhat.com/support/errata/RHSA-2002-060.html来源: OSVDB
名称: 5350
链接:http://www.osvdb.org/5350来源: XF
名称: zope-proxy-role-privileges(8334)
链接:http://www.iss.net/security_center/static/8334.php来源: BUGTRAQ
名称: 20020301 [matt@zope.com: [Zope-Annce] Zope Hotfix 2002-03-01 (Ownership Roles Enforcement)]
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=101503023511996&w=2
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END