|
Family: Ubuntu Local Security Checks --> Category: infos
USN229-1 : zope2.8 vulnerability Vulnerability Scan
Vulnerability Scan Summary zope2.8 vulnerability
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- zope2.8
- zope2.8-sandbox
Description :
Zope did not deactivate the file inclusion feature when exposing
RestructuredText functionalities to untrusted users. A remote user
with the privilege of editing Zope webpages with RestructuredText
could exploit this to expose arbitrary files that can be read with the
rights of the Zope server, or execute arbitrary Zope code.
Solution :
Upgrade to :
- zope2.8-2.8.1-5ubuntu0.1 (Ubuntu 5.10)
- zope2.8-sandbox-2.8.1-5ubuntu0.1 (Ubuntu 5.10)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|