Input validation error in Zope - CVE-2006-3458

 

Input validation error in Zope - CVE-2006-3458

Published: October 3, 2018 / Updated: June 17, 2025


Vulnerability identifier: #VU111189
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2006-3458
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Zope
Affected software:
Zope

Detailed vulnerability description

The vulnerability allows a local user to gain access to sensitive information.

Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.


How to mitigate CVE-2006-3458

Install update from vendor's website.

Sources