SB2017101085 - Input validation error in Zope
Published: October 10, 2017 Updated: June 17, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2001-0128)
The vulnerability allows a local user to execute arbitrary code.
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
Remediation
Install update from vendor's website.
References
- ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000365
- http://www.debian.org/security/2000/20001219
- http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-083.php3
- http://www.osvdb.org/6284
- http://www.redhat.com/support/errata/RHSA-2000-127.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5777