From: "Brian Lloyd" <brian.lloyd@zope.com> To: <zope-announce@zope.org>, <zope@zope.org> Subject: [Zope] SECURITY ALERT: Hotfix for dtml format method checking Date: Mon, 1 Oct 2001 17:31:31 -0400 Hello all, Shane Hathaway recently identified a potential security issue in Zope that could affect sites that let untrusted users write DTML code. The issue affects Zope versions 2.2.0 through 2.4.1. The issue involves the "fmt" attribute of dtml-var tags. Without this correction, Zope does not check security access to methods invoked through "fmt". This issue could allow partially trusted users with enough knowledge of Zope to call, in a limited way, methods they would not otherwise be allowed to access. We highly recommend that any Zope site running Zope 2.2.0 through Zope 2.4.1 have this hotfix product installed to mitigate the issue. Zope 2.4.2 will contain a fix for the issue, at which time the hotfix can be removed. http://www.zope.org/Products/Zope/Hotfix_2001-09-28/README.txt http://www.zope.org/Products/Zope/Hotfix_2001-09-28/Hotfix_2001-09-28.tgz Brian Lloyd brian@zope.com Software Engineer 540.361.1716 Zope Corporation http://www.zope.com _______________________________________________ Zope maillist - Zope@zope.org http://lists.zope.org/mailman/listinfo/zope ** No cross posts or HTML encoding! ** (Related lists - http://lists.zope.org/mailman/listinfo/zope-announce http://lists.zope.org/mailman/listinfo/zope-dev )