SB2010091001 - Input validation error in Zope
Published: September 10, 2010 Updated: June 17, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2010-3198)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.
Remediation
Install update from vendor's website.
References
- http://www.securityfocus.com/bid/42939
- http://www.vupen.com/english/advisories/2010/2275
- http://www.zope.org/Products/Zope/2.10.12/CHANGES.txt
- http://www.zope.org/Products/Zope/2.11.7/CHANGES.txt
- https://bugs.launchpad.net/zope2/+bug/627988
- https://mail.zope.org/pipermail/zope-announce/2010-September/002247.html