Input validation error in Zope - CVE-2001-0128
Published: October 10, 2017 / Updated: June 17, 2025
Vulnerability identifier: #VU111198
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2001-0128
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Zope
Affected software:
Zope
Zope
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary code.
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
How to mitigate CVE-2001-0128
Install update from vendor's website.
Sources
- ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000365
- http://www.debian.org/security/2000/20001219
- http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-083.php3
- http://www.osvdb.org/6284
- http://www.redhat.com/support/errata/RHSA-2000-127.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5777