Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

2013-01-27 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/27/2013 11:55 AM, David Glick (Plone) wrote: > On 1/27/13 6:00 PM, Tres Seaver wrote: >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >> >> On 01/27/2013 08:49 AM, Julien Cristau wrote: >>> On Mon, Nov 26,

Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

2013-01-27 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/27/2013 08:49 AM, Julien Cristau wrote: > On Mon, Nov 26, 2012 at 18:53:58 +0900, Arnaud Fontaine wrote: > >> Tres Seaver writes: >> >>>> * CVE-2012-5505 (zope.traversing: atat.py) >>>> http://pl

Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

2012-11-25 Thread Tres Seaver
6/21 That "fix" is also disputed: hiding the "default" view from the '@@' name does not actually improve security at all. There is a Launchpad bug where it is being debated (#1079225), but that bug is still in "Private Security" mode. The correct fix is to c