|
Family: Debian Local Security Checks --> Category: infos
[DSA490] DSA-490-1 zope Vulnerability Scan
Vulnerability Scan Summary DSA-490-1 zope
Detailed Explanation for this Vulnerability Test
A vulnerability has been discovered in the index support of the
ZCatalog plug-in in Zope, an open source web application server. A
flaw in the security settings of ZCatalog allows anonymous users to
call arbitrary methods of catalog indexes. The vulnerability also
allows untrusted code to do the same.
For the stable distribution (woody) this problem has been fixed in
version 2.5.1-1woody1.
For the unstable distribution (sid) this problem has been fixed in
version 2.6.0-0.1 and higher.
We recommend that you upgrade your zope package.
Solution : http://www.debian.org/security/2004/dsa-490
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|