<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="http://plone.org/products/plone/security/advisories/all-advisories/RSS">
  <title>Plone Security Advisories</title>
  <link>http://plone.org</link>

  <description>
    
      
    
  </description>

  

  
            <syn:updatePeriod>daily</syn:updatePeriod>
            <syn:updateFrequency>1</syn:updateFrequency>
            <syn:updateBase>2010-06-23T17:02:22Z</syn:updateBase>
        

  <image rdf:resource="http://plone.org/logo.png"/>

  <items>
    <rdf:Seq>
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/security-announcement-zope-hotfix-20111024"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/20110928"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/CVE-2011-2528"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/hotfix-error-hotfix20110531-version-1"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/CVE-2011-1950"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/CVE-2011-1949"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/CVE-2011-1948"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/cve-2011-0720"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/CVE-2010-2422"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/cve-2009-0662"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/cve-2008-0164"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/cve-2007-5741"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/zope-xss-vulnerability-2007-03-20"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/cve-2006-4249"/>
      
      
        <rdf:li rdf:resource="http://plone.org/products/plone/security/advisories/cve-2006-4684"/>
      
    </rdf:Seq>
  </items>

</channel>


  <item rdf:about="http://plone.org/products/plone/security/advisories/security-announcement-zope-hotfix-20111024">
    <title>Security announcement: Zope Hotfix 20111024</title>
    <link>http://plone.org/products/plone/security/advisories/security-announcement-zope-hotfix-20111024</link>
    <description>The latest Zope security announcement does not affect most Plone installations.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><b><span> </span></b><span>The Zope Security Team has announced a hotfix,</span><span> Products.Zope_Hotfix_20111024,</span><span> for a vulnerability in the Zope Application Server, versions 2.12.x and Zope 2.13.x</span>.</p>
<p><span> <b>Most Plone installations are not vulnerable and do not need the  hotfix. Please read this announcement carefully for instructions on how  to determine whether or not you need to apply the hotfix.</b></span></p>
<p><span>The  announced vulnerability is in Zope's default authentication system.  When a Plone site is installed in a Zope database, the Plone  installation usually replaces the basic Zope authentication system with  the Pluggable Authentication System (PAS). PAS is not vulnerable to this  problem.</span></p>
<p><span>You may verify that you are using PAS by using the Zope Management  Interface to examine the acl_users object in the root of your Zope  database.</span></p>
<p><span>If the title of the object reads "</span><b>User Folder         at <a href="http://localhost:8080/manage_workspace" target="_blank"> /</a><a href="http://localhost:8080/acl_users/manage_workspace" target="_blank">acl_users</a></b><span>", your system is vulnerable and you should apply the hotfix.</span></p>
<p><span><span>If the title of the object reads "</span></span><b>Pluggable Auth Service         at <a href="http://localhost:8080/manage_workspace" target="_blank"> /</a><a href="http://localhost:8080/acl_users/manage_workspace" target="_blank">acl_users</a></b><span>", your system is not vulnerable.</span></p>
<p><b><span>Versions Affected:</span></b><span> </span>Zope 2.12.x &lt;= 2.12.20 and Zope 2.13.x &lt;= 2.13.10 that do not have the Pluggable Authentication System installed.</p>
<p><b>Versions Not Affected:</b> Zope installations where Plone installation has replaced the Zope baseline authentication system.</p>
<p><span>See the </span><a href="http://permalink.gmane.org/gmane.comp.web.zope.announce/1510" target="_blank">Zope Hotfix Announcement</a><span> for details on installing the hotfix.</span></p>
<p><b><span>General questions</span></b><span><b> about this announcement</b>, Plone patching procedures, and availability of support may be addressed to the </span><a href="http://plone.org/support" target="_blank"><span>Plone support forums</span></a><span>. If you have specific questions about this vulnerability or its handling, contact the </span><a href="mailto:security@plone.org" target="_blank"><span>Plone Security Team</span></a><span>.</span></p>
<p><b><span>To report potentially security-related issues</span></b><span>, please send a mail to the Plone Security Team at </span><span><a href="mailto:security@plone.org" target="_blank">security@plone.org</a></span><span>. The security team is always happy to credit individuals and companies who make responsible disclosures.</span></p>]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Steve McMahon</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2011-10-27T21:27:30Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/20110928">
    <title>Security vulnerability announcement: 20110928 - Arbitrary Code Execution</title>
    <link>http://plone.org/products/plone/security/advisories/20110928</link>
    <description>A vulnerability in Zope 2.12.x and Zope 2.13.x that allows execution of arbitrary code by anonymous users.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>The fix  was released at 15:00 UTC on Tuesday 4th October, 2011.</p>
<p><a class="external-link" href="../../../plone-hotfix/releases/20110928"><b>Full installation instructions.</b></a></p>
<p><span>This is a severe vulnerability that allows an unauthenticated attacker to employ a carefully crafted web request to execute arbitrary commands with the privileges of the Zope/Plone service.</span></p>
<p><strong>CVE-2011-3587</strong></p>
<p><strong><span>Versions Affected:</span></strong><span> </span><span>Plone 4.0 (through 4.0.9); Plone 4.1; Plone 4.2 (a1 and a2); Zope 2.12.x and Zope 2.13.x.</span></p>
<p><span><strong>Versions Not Affected:</strong> </span><span>Versions of Plone that use Zope other than Zope 2.12.x and Zope 2.13.x.</span><br /><span></span></p>
<p><strong><span>This is a pre-announcement.</span></strong><span> Due to the sev</span><span>erity of this issue we are providing an advance warning of an upcoming patch, which will be released on</span><a href="cve-2011-0720"><span> </span></a><a class="external-link" href="../../../plone-hotfix/releases/20110928"><span></span><span></span><span>this page</span></a><span> at </span><strong><span>2011-10-04 15:00 UTC</span></strong><span>.</span></p>
<h3><span>What you should do in advance of patch availability</span><span></span></h3>
<p><span>Due to the nature of the vulnerability, the security team has decided to pre-announce that a fix is upcoming before disclosing the details. This is to ensure that concerned users can plan around the release.  As the fix being published will make the details of the vulnerability public, we are recommending that all users plan a maintenance window for 30 minutes either side of the announcement where your site is completely inaccessible in which to install the fix.</span></p>
<p><span>Meanwhile, we STRONGLY recommend that you take the following steps to protect your site:</span></p>
<ol>
<li style="list-style-type: decimal; "><span>Make sure that the Zope/Plone service is running with with minimum privileges. Ideally, the Zope and ZEO services should be able to write only to log and data directories.</span></li>
<li style="list-style-type: decimal; "><span>Use an intrusion detection system that monitors key system resources for unauthorized changes.</span></li>
<li style="list-style-type: decimal; "><span>Monitor your Zope, reverse-proxy request and system logs for unusual activity.</span></li>
</ol>
<p><span>In this case, these are standard precautions that should be employed on any production system.</span></p>
<h3><span>Extra help</span><span></span></h3>
<p><span>Should you not have in-house server administrators or a service agreement looking after your website you can find consultancy companies on</span><a href="http://plone.net/"><span> </span><span>plone.net</span></a><span>.</span></p>
<p><span>There is also </span><a href="../../../../support"><span>free support</span></a><span> available online via Plone mailing lists and the Plone IRC channels.</span></p>
<hr />
<h2><span>Questions and Answers</span></h2>
<p><span></span><br /><strong><span>Q: When will the patch be made available?</span><br /></strong><span>A: The Plone Security Team will release the patch at </span><span>2011-10-04 15:00 UTC</span><span>.</span></p>
<p><strong><span></span></strong><strong><span>Q. What will be involved in applying the patch?</span><br /></strong><span>A. Patches are made available as tarball-style archives that may be unpacked into the “products” folder of a buildout installation and as Python packages that may be installed by editing a buildout configuration file and running buildout.  Patching is generally easy and quick to accomplish.</span><strong><span></span></strong></p>
<p><strong><span>Q: How was this vu</span><span>lnerability found?</span><br /></strong><span>A: This issue was found as part of a routine audit performed by the Plone Security team.</span></p>
<p><span><strong></strong></span><span><strong>Q: My site is highly visible and mission-critical. I hear the patch has already been developed. Can I get the fix before the release date?</strong></span><br /><span>A: No. The patch will be made available to all users at the same time. There are no exceptions.</span></p>
<p><strong><span></span></strong><strong><span>Q: If the patch has been developed already, why isn't it already made available to the public?</span><br /></strong><span>A: The Security Team is still testing the patch and running various scenarios thoroughly. The team is also making sure everybody has appropriate time to plan to patch their Plone installation(s). Some consultancy organizations have hundreds of sites to patch and need the extra time to coordinate their efforts with their clients.</span></p>
<p><strong><span>Q: How does one exploit the vulnerability?</span><br /></strong><span>A: This information will not be made available until after the patch is made available.</span><strong><span></span></strong><strong><span></span></strong></p>
<p><strong><span>General questions</span></strong><span><strong> about this announcement</strong>, Plone patching procedures, and availability of support may be addressed to the </span><a href="../../../../support"><span>Plone support forums</span></a><span>. If you have <strong>specific questions</strong> about this vulnerability or its handling, contact the </span><a href="mailto:security@plone.org"><span>Plone Security Team</span></a><span>.</span></p>
<p><strong><span>To report potentially security-related issues</span></strong><span><strong>,</strong> please send a mail to the Plone Security Team at </span><span>security@plone.org</span><span>. The security team is always happy to credit individuals and companies who make responsible disclosures.</span></p>
<h3><span>Information for vulnerability database maintainers</span></h3>
<p><strong><span>CVSS Base Score</span></strong><br /><span>7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P/E:P/RL:O/RC:C)</span><br /><strong><span>Impact Subscore</span></strong><br /><span>6.4</span><br /><strong><span>Exploitability Subscore</span></strong><br /><span>10</span><br /><strong><span>CVSS Temporal Score</span><br /></strong><span>5.9</span><span></span><br /><strong><span>Credit</span><br /></strong><span>Alan Hoey</span></p>]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Steve McMahon</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2011-09-28T20:30:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/CVE-2011-2528">
    <title>Security vulnerability announcement: CVE-2011-2528 – Privilege escalation</title>
    <link>http://plone.org/products/plone/security/advisories/CVE-2011-2528</link>
    <description>A highly serious vulnerability in Zope that allows unauthorised access</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>The fix  was released at 15:00 UTC on Tuesday 28th June, 2011.</p>
<p><a class="external-link" href="../../../plone-hotfix/releases/20110622"><strong>Full installation instructions.</strong></a></p>
<h3>Who should apply the patch</h3>
<ul>
<li><strong>Plone 4.x users</strong> must apply this patch or update to Zope2 2.12.19 (Plone 4.0) or 2.13.8 (Plone 4.1).</li>
<li><strong>Zope 2.12/2.13 users</strong> must apply this patch or update to Zope2 2.12.19 or 2.13.8.</li>
<li><strong>Plone 3.x users:</strong> the vulnerability was inadvertently backported by the previous hotfix <a class="external-link" href="../../../plone-hotfix/releases/CVE-2011-0720">http://plone.org/products/plone-hotfix/releases/CVE-2011-0720</a> (PloneHotfix20110720). Plone 3.x users should install both PloneHotfix20110720 and this hotfix to make sure that they are protected against both sets of vulnerabilities.</li>
<li><strong>Zope 2.10/2.11 users who are not using Plone:</strong> Zope 2.10 and 2.11 users who have not installed PloneHotfix20110720 are not affected by this vulnerability, and should not apply the patch. You should, however, make sure that you are running either Zope 2.10.13 or Zope 2.11.8  and PluggableAuthService 1.5.5, 1.6.5 or 1.7.5 which include fixes for the vulnerabilities in CVE-2011-0720. Please make sure that you have not installed PloneHotfix20110720; remove it if you have.</li>
</ul>
<p>Other versions are not affected. Plone 2.5 and Zope 2.8/2.9 are unaffected; you should not install this hotifx on those sites.</p>
<h3>Extra help</h3>
<p>Should you not have in-house server administrators or a service agreement looking after your website you can find consultancy companies under the <a class="external-link" href="../../../../providers">providers section</a>.</p>
<p>There is also <a href="../../../../support">free support</a> available online.</p>
<h3>Questions and Answers</h3>
<p><strong>Q: When will the patch be made available?</strong></p>
<p>A: The Plone and Zope Security Teams released the patch at 15:00 UTC (11:00am US EDT) on Tuesday 28th June, 2011.</p>
<p><strong>Q: How was this vulnerability found?</strong></p>
<p>A: This issue was found as part of a routine audit performed by the Zope and Plone Security teams.</p>
<p><strong>Q: My site is highly visible and mission-critical. I hear the patch has already been developed. Can I get the fix before the release date?</strong></p>
<p>A: The Security Team has made the decision to not allow any early release of this patch so as to reduce the risks of exploitation. This decision applies to everyone, even Plone Foundation Members and Board members.</p>
<p><strong>Q: If the patch has been developed already, why isn't it already made available to the public?</strong></p>
<p>A: The Security Team is still testing the patch and running various scenarios thoroughly. The team is also making sure everybody has appropriate time to plan to patch their Plone installation(s). Some consultancy organizations have hundreds of sites to patch and need the extra time to coordinate their efforts with their clients.</p>
<p><strong>Q: How does one exploit the vulnerability?</strong></p>
<p>A: For obvious security reasons, the information will not be made available until after the patch is made available.</p>
<p><strong>Q: Are there any third-party products I can use to protect my site until the patch is available?</strong></p>
<p>A: No.</p>
<p><strong>Q: Will making my database read-only protect my site?</strong></p>
<p>A: This will not protect against unauthorized data access.</p>
<p><strong>Q: What is the hotfix package be named?</strong></p>
<p>A: Products.Zope_Hotfix_20110622</p>
<p><strong>Q: I already applied version 1.0 of the hotfix to my site. Do I need to install version 1.0-release2 now?</strong></p>
<p><span style="padding-left: 0px; ">A: No. The code has not changed. The 1.0 release included a </span>__MACOSX resource fork which was confusing for non Mac OS X users.</p>
<p><b>Q: I see "ImportError: No module named traversing" on startup after installing the hotfix.</b></p>
<p>You have installed the hotfix onto a Plone 2.5 or Zope 2.8/2.9 site. The Hotfix is not required; you should remove it.</p>]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Laurence Rowe</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2011-06-28T12:00:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/hotfix-error-hotfix20110531-version-1">
    <title>Hotfix Error: Hotfix20110531 version 1.0 is incomplete</title>
    <link>http://plone.org/products/plone/security/advisories/hotfix-error-hotfix20110531-version-1</link>
    <description>A critical flaw has been found in version 1.0 of Hotfix20110531, an update is now available</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<p>The Plone security team is sorry to announce that a flaw in Hotfix20110531 released on the 1st June 2011 has been found.&nbsp; The escalation of privileges attack was not blocked on Plone 4, despite having the fix installed.&nbsp;</p>
<p>As such, we have released version 2.0 of this fix which contains a tighter check for potential attacks, which is available at <a class="external-link" href="../../../plone-hotfix/releases/20110531">http://plone.org/products/plone-hotfix/releases/20110531</a>. If you have already installed Hotfix20110531 on Plone 4 you need to update 
to version 2.0.&nbsp; For Plone 3.x and Plone 2.x, if Hotfix20110531 is not yet 
installed you should install version 2.0.&nbsp; If you have version 1.0 of Hotfix20110531 installed on Plone 3.x or 2.x you do not need to upgrade.</p>
<p>For those who used buildout to install the fix all that needs be done is for it to be re-run to pick up the latest versions.</p>
<p>We apologise for the inconvenience this has caused; we will be doing a postmortem on this fix to further improve our security patch release procedures in the coming weeks.</p>
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Matthew Wilkes</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2011-06-02T16:45:45Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/CVE-2011-1950">
    <title>Security vulnerability announcement: CVE-2011-1950 – An escalation of privileges attack</title>
    <link>http://plone.org/products/plone/security/advisories/CVE-2011-1950</link>
    <description>A vulnerability in plone.app.users affecting Plone 4.0 and 4.1.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<p>This is an escalation of privileges attack which makes it possible for an authenticated Plone user to edit the properties of other users, bypassing authorization checks.</p>
<p>As this vulnerability was disclosed publicly it is highly recommended that all site administrators and their privileged users reset their passwords.</p>
<div class="pane">
<h2>Fix</h2>
<p>
The Hotfix for this vulnerability is <a href="../../../plone-hotfix/releases/20110531">Hotfix 20110531</a>.</p>
</div>
<h3 class="callout">*** IMPORTANT ***: The original release of this hotfix that was made on May 31 had a critical flaw.&nbsp; Please make sure you are using version 2.0 of the hotfix. The Plone security team apologizes for the error.</h3>
<p>&nbsp;</p>
<h3>Information for security researchers<br /></h3>
<strong>CVSS Base Score</strong>
<p>6.8</p>
<em>Impact Subscore</em>
<p>6.9</p>
<em>Exploitability Subscore</em>
<p>8</p>
<strong>Overall CVSS Score</strong>
<p>6.8</p>
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Matthew Wilkes</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2011-06-01T15:50:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/CVE-2011-1949">
    <title>Security vulnerability announcement: CVE-2011-1949 – A persistent cross site scripting vulnerability</title>
    <link>http://plone.org/products/plone/security/advisories/CVE-2011-1949</link>
    <description>A vulnerability in Plone versions using Products.PortalTransforms, including Plone 2.1 through 4.1.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<p>This is a persistent cross-site scripting (XSS) attack. It allows a user to craft markup that bypasses Plone's safe_html filter to insert and save arbitrary HTML with malicious content.</p>
<p>This vulnerability was discovered and responsibly disclosed by Daniel Berlin and Dan Bentley, both of Google, and independently by Brian Peters, an independent researcher.</p>
<div class="pane">
<h2>Fix</h2>
<p>
The Hotfix for this vulnerability is <a href="../../../plone-hotfix/releases/20110531">Hotfix 20110531</a>.</p>
</div>
<h3 class="callout">*** IMPORTANT ***: The original release of this hotfix that was made on May 31 had a critical flaw.&nbsp; Please make sure you are using version 2.0 of the hotfix. The Plone security team apologizes for the error.</h3>
<div>&nbsp;</div>
<h3>Information for security researchers<br /></h3>
<strong>CVSS Base Score</strong>
<p>6.4</p>
<em>Impact Subscore</em>
<p>4.9</p>
<em>Exploitability Subscore</em>
<p>10</p>
<strong>Overall CVSS Score</strong>
<p>6.4</p>
<p>&nbsp;</p>
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Matthew Wilkes</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2011-06-01T15:50:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/CVE-2011-1948">
    <title>Security vulnerability announcement: CVE-2011-1948 – A reflected cross site scripting vulnerability</title>
    <link>http://plone.org/products/plone/security/advisories/CVE-2011-1948</link>
    <description>A vulnerability in all Plone versions that allows specially crafted URLs to return arbitrary content.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<p>This is a reflected cross site scripting attack, that is, it is exploitable by special URLs that contain the malicious content.&nbsp;</p>
<p>This vulnerability was responsibly disclosed by J. Greil after discovery by S. Streichsbier, both of <a class="external-link" href="http://www.sec-consult.com">SEC Consult</a>.</p>
<div class="pane">
<h2>Fix</h2>
<p>
The Hotfix for this vulnerability is <a href="../../../plone-hotfix/releases/20110531">Hotfix 20110531</a>.</p>
</div>
<h3 class="callout">*** IMPORTANT ***: The original release of this hotfix that was made on May 31 had a critical flaw.&nbsp; Please make sure you are using version 2.0 of the hotfix. The Plone security team apologizes for the error.</h3>
<div>&nbsp;</div>
<h3>Information for security researchers<br /></h3>
<strong>CVSS Base Score</strong>
<p>5</p>
<em>Impact Subscore</em>
<p>2.9</p>
<em>Exploitability Subscore</em>
<p>10</p>
<strong>Overall CVSS Score</strong>
<p>5</p>
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Matthew Wilkes</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2011-06-01T15:50:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/cve-2011-0720">
    <title>Security vulnerability announcement: CVE-2011-0720 - Privilege escalation</title>
    <link>http://plone.org/products/plone/security/advisories/cve-2011-0720</link>
    <description>A vulnerability in Plone 2.5 to Plone 4.0 that allows anonymous users to gain manager access to a Plone site.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>This is an escalation of privileges attack that can be used by anonymous users to gain access to a Plone site's administration controls, view unpublished content, create new content and modify a site's skin.  The sandbox protecting access to the underlying system is still in place, and it does not grant access to other applications running on the same Zope instance.</p>
<p>All versions of Plone since 2.5 are affected, viz. 2.5, 3.0, 3.1, 3.2, 3.3, 4.0; including all minor and development revisions of these versions.  Plone versions prior to 2.5, including Plone 1.0, Plone 2.0 and Plone 2.1 are not affected.</p>
<p>The fix was released at 1621 UTC on Tuesday 8th February.</p>
<p><b><a class="external-link" href="../../../plone-hotfix/releases/CVE-2011-0720/">Full installation instructions.</a></b></p>
<p><span class="Apple-style-span"> </span></p>
<h3>Extra help</h3>
<p>Should you not have in-house server administrators or a service agreement looking after your website you can find consultancy companies on <a class="external-link" href="http://plone.net/">plone.net</a>.</p>
<p>There is also <a href="../../../../support">free support</a> available online.</p>
<p> </p>
<h3>Previous Workaround</h3>
<p>Due to the nature of the vulnerability, the security team decided to pre-announce that a fix is upcoming before disclosing the details, to ensure that concerned users can plan around the release.  As the fix being published will make the details of the vulnerability public we are recommending that all users plan a maintenance window for 30 minutes either side of the announcement where your site is completely inaccessible in which to install the fix.</p>
<p>We recommended to people that could not have a scheduled downtime that they take one of the following steps to protect their site from before the announcement until you apply the fix:</p>
<ol>
<li>Make your database <a class="external-link" href="../../../../documentation/faq/plone-read-only-mode">read-only</a>.</li>
<li>Alternatively, if this option isn't possible due to not using one of our standard ZODB backends, <a class="external-link" href="../../../../documentation/kb/disable-logins-for-a-plone-site">disable logins</a> by filtering HTTP authentication and cookies in Apache or Varnish.</li>
</ol>
<p>These did not need to be in place for the entire week but should already be in place before the fix and vulnerability details are released next week.  By preventing modifications to your site and patching your site quickly you remove the incentive for potential attackers to attempt this attack.</p>
<h3>Information for vulnerability database maintainers</h3>
<dl> <dt>CVSS Base Score</dt> <dd>7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:T/RC:C)</dd> <dt>Impact Subscore</dt> <dd>6.4</dd> <dt>Exploitability Subscore</dt> <dd>10</dd> <dt>CVSS Temporal Score</dt> <dd>6.4</dd> <dt>Credit</dt> <dd>Alan Hoey </dd></dl> 
<hr />
<h3><b>Questions and Answers</b></h3>
<p><b><br /></b></p>
<p><b>Q: When will the patch be made available?</b></p>
<p>A: It is available now! The Plone Security Team released the patch at 16:21 GMT (11:21am US ET) on Tuesday February 8th, 2011.</p>
<p><b>Q: How was this vulnerability found?</b></p>
<p>A: This issue was found as part of a routine audit performed by the Plone Security team.</p>
<p><b>Q: My site is highly visible and mission-critical. I hear the patch has already been developed. Can I get the fix before the release date?</b></p>
<p>A: The Security Team has made the decision to not allow any early release of this patch so as to reduce the risks of exploitation. This decision applies to everyone, even Plone Foundation Members and Board members.</p>
<p><b>Q: If the patch has been developed already, why isn't it already made available to the public?</b></p>
<p>A: The Security Team is still testing the patch and running various scenarios thoroughly. The team is also making sure everybody has appropriate time to plan to patch their Plone installation(s). Some consultancy organizations have hundreds of sites to patch and need the extra time to coordinate their efforts with their clients.</p>
<p><b>Q: How does one exploit the vulnerability?</b></p>
<p>A: For obvious security reasons, the information will not be made available until after the patch is made available.</p>
<p><b>Q: How can I be sure my website hasn't already been compromised?</b></p>
<p>A: Yes, there is a script which will check your zope or apache log files for suspicious activity.  <a class="external-link" href="../../../plone-hotfix/releases/CVE-2011-0720/logchecker.py">Download it</a> then run it as: python logchecker.py /path/to/your/instance-Z2.log</p>
<p><b>Q: Are there any third-party products I can use to protect my site until the patch is available?</b></p>
<p>A: No.</p>
<p><b>Q: I already applied version 1.0 of the hotfix to my site. Do I need to install version 1.1 now?</b></p>
<p>A: You only need version 1.1 of the hotfix if you got exceptions when trying to use version 1.0. Version 1.1 fixes 2 minor installation edge cases but does not change the nature of the fix that is applied.</p>
<ul>
</ul>]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Matthew Wilkes</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2011-02-01T10:20:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/CVE-2010-2422">
    <title>CVE-2010-2422: HTML injection in safe_html</title>
    <link>http://plone.org/products/plone/security/advisories/CVE-2010-2422</link>
    <description>This update fixes a flaw in Plone's HTML filtering that allows arbitrary code to be injected into pages.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<p><strong>Update:</strong> we now have an official CVE number: CVE-2010-2422</p>
<p>The fix is included in an update of PortalTransforms.</p>
<div id="parent-fieldname-text" class="plain kssattr-atfieldname-text kssattr-templateId-newsitem_view kssattr-macro-text-field-view">
<p>Alan Hoey of&nbsp;<a class="external-link" href="http://www.teamrubber.com/">Team Rubber</a>
found a bug in the html filtering of all Plone versions. Users who can
create content can exploit this flaw to circumvent the normal HTML
filtering.</p>
<p>This issue has been assigned the number&nbsp;<a class="external-link" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2422">CVE-2010-2422</a>.</p>
<h2><a name="affected-versions"></a>Affected versions</h2>
<p>All Plone releases since 2.1 are affected.</p>
<h2>Installing the hotfix</h2>
<h3><a name="for-plone-3-0"></a></h3>
<h3>Installation for Plone 2.1 - 3.1 users</h3>
<div>
<div>&nbsp;</div>
</div>
<p>To install this hotfix <a class="external-link" href="../../../plone-hotfix/releases/20100612/plonehotfix20100612-1.tar.gz">download and unzip the distribution</a> and add the directory PloneHotfix20100612 to your instance products directory. If the hotfix has been successfully added you will see the following message when starting the instance in foreground mode:</p>
<pre>2010-06-12 23:54:28 INFO PloneHotfix20100612 safe_html patched</pre>
<div>
<div>&nbsp;</div>
<h3>Installation for Plone 3.2 and 3.3 users</h3>
<div>
<div>&nbsp;</div>
<p>Although this hotfix will work with any version of Plone, users of Plone 3.2&nbsp;to Plone 3.3.5 should instead add the following to their buildout configuration files and re-run buildout:</p>
</div>
<div>
<pre>[versions]
Products.PortalTransforms = 1.6.12</pre>
<p>There will be no confirmation message on start-up, so the presence of the fix&nbsp;can be verified by checking the version number of PortalTransforms in the Zope&nbsp;Control Panel.</p>
<div>&nbsp;</div>
</div>
</div>
<h2>Reported incidents</h2>
<p>No incidents of this vulnerability being exploited have been reported.</p>
<h2>References</h2>
<dl><dt>CVE</dt><dd><span class="Apple-style-span"><a class="external-link" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2422">CVE-2010-2422</a>.</span><span class="Apple-style-span">&nbsp;</span></dd><dt><br /></dt></dl>
</div>
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Matthew Wilkes</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2010-06-19T14:55:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/cve-2009-0662">
    <title>CVE-2009-0662: Authentication flaw in login form</title>
    <link>http://plone.org/products/plone/security/advisories/cve-2009-0662</link>
    <description>This update fixes a flaw in the login form handling which allowed authenticated users to assume another identity.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<p>The fix is included in an update of PlonePAS, the Pluggable Authentication System.</p>
<ul><li><a title="Affected versions" href="#affected-versions">Affected Plone versions list</a><br /></li><li><a title="For Plone 3.0.x and 3.1.x" href="#for-plone-3-0">Instructions for installing the fix on Plone 3.0.x or 3.1.x</a></li><li><a title="For Plone 3.2.x" href="#for-plone-3-2">Instructions for Plone 3.2.x</a><br /></li></ul>
<p>Karen Chan of <a href="http://www.isotoma.com/">Isotoma Limited</a> found a bug in the login form handling of Plone 3.x. An already authenticated user could exploit this error and assume the identity of another user.</p>
<p>This issue has been assigned <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0662">CVE-2009-0662</a>.</p>
<h2><a name="affected-versions"></a>Affected versions</h2>
<p>All Plone 3.x releases are affected.</p>
<p>Plone 2.5 and earlier releases are not affected.</p>
<h2>Installing the hotfix</h2>
<h3><a name="for-plone-3-0"></a>For Plone 3.0.x and 3.1.x</h3>
<p>If you are using Plone 3.0.x or 3.1.x you can download and install a new PlonePAS product release.&nbsp;The product can be installed as a normal Plone product:</p>
<ul style="list-style-type: disc;"><li>For <strong>Plone 3.0</strong> use <a title="PlonePAS 3.2.2" class="internal-link" href="../../../plonepas/releases/3.2.2">version 3.2.2 of PlonePAS</a>. Verify the md5 hash of the hotfix package — it should be "f88c542bdf8e22674d284418e58c0da8".</li><li>For <strong>Plone 3.1</strong> use <a title="PlonePAS 3.9" class="internal-link" href="../../../plonepas/releases/3.9">version 3.9 of PlonePAS</a>. Verify the md5 hash of the hotfix package — it should be "9ddc4d9b3505fe71f2c3e17513680c50".</li><li>Extract it in the Products directory of your Zope instance.<br /></li><li>Restart Zope</li></ul>
<p>If you're using Plone 3.0 or Plone 3.1 with buildout you can update the productdistros section of your buildout.cfg to download the hotfix for you, as follows:</p>
<h3><strong>Plone 3.0:</strong><br /></h3>
<pre>[productdistros]
recipe = plone.recipe.distros
urls =
    http://plone.org/products/plonepas/releases/3.2.2/PlonePAS-3.2.2.tar.gz
nested-packages =
version-suffix-packages =</pre>
<h3><strong>Plone 3.1:</strong><br /></h3>
<pre>[productdistros]
recipe = plone.recipe.distros
urls =
    http://plone.org/products/plonepas/releases/3.9/PlonePAS-3.9.tar.gz
nested-packages =
version-suffix-packages =</pre>
<h3><a name="for-plone-3-2"></a>For Plone 3.2.x</h3>
<p>If you are using Plone 3.2.x you should use the Products.PlonePAS 3.9 egg release.&nbsp;</p>
<h3>With buildout</h3>
<p>If you are using buildout you can update the version pin for this package by adding this entry to your buildout.cfg file:</p>
<pre>[versions]
Products.PlonePAS = 3.9</pre>
<p>If your buildout.cfg already has a "[versions]" part, just add the "Products.PlonePAS = 3.9" line. If there is no "[versions]" section, just add one to the end of your buildout.cfg file.</p>
<p>After making this change you need to stop Zope, run bin/buildout, and restart Zope.</p>
<h3>Not using buildout</h3>
<p>If you are not using buildout you can use the easy_install command to install an updated version of Products.PlonePAS:</p>
<pre>$ easy_install -U Products.PlonePAS==3.9</pre>
<p>Restart Zope.</p>
<h2>Reported incidents</h2>
<p>No incidents of this vulnerability being exploited have been reported.</p>
<h2>References</h2>
<dl><dt>CVE</dt><dd><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0662">CVE-2009-0662 </a></dd></dl>
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Wichert Akkerman</dc:creator>
    <dc:rights></dc:rights>
    
      <dc:subject>Security</dc:subject>
    
    <dc:date>2009-04-21T10:15:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/cve-2008-0164">
    <title>CVE-2008-0164: Cross Site Request Forging (CSRF) security vulnerability</title>
    <link>http://plone.org/products/plone/security/advisories/cve-2008-0164</link>
    <description>This update protects security sensitive forms in Plone from cross site request forgery (CSRF) attacks.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>Adrian Pastor from security firm <span class="link-external"><a href="http://www.procheckup.com/">ProCheckUp Ltd</a></span> reported that Plone is vulnerable to the <span class="link-external"><a href="http://en.wikipedia.org/wiki/CSRF">cross site request forgery</a></span>
class of attacks. CSRF attacks work against people with a valid session
on a Plone site: an attacker can — by tricking them (or their browser)
to make an HTTP request to the site — use their active session and
change security sensitive settings such as the users email address.</p>
<p>A framework to protect Plone against CSRF attacks has been developed in the form of <a title="PLIP #224: CSRF protection framework " href="../../../plone/roadmap/224">PLIP 224</a> for <a href="../../../../download">Plone 3.1</a> and is available for Plone 3.0 via <a href="../CVE-2008-0164">Plone Hotfix CVE-2008-0164</a>.
For older versions of Plone (i.e. the 2.x and 1.0 series), please
upgrade. If you are unable to upgrade, see the Temporary Workaround
section below.</p>
<p>This issue has been assigned <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0164">CVE-2008-0164</a>.</p>
<h2>Affected versions</h2>
<p>All Plone releases are affected.</p>
<p><a href="../../../../download">Plone 3.1 and later</a> includes a fix for this issue, and does not need this hotfix.</p>
<h2>Installing the hotfix</h2>
<p>If you are using Plone 3.0.x you can download and install <a href="../CVE-2008-0164">Plone Hotfix CVE-2008-0164</a>. The hotfix can be installed as a normal Plone product:</p>
<ul><li>Verify the md5 hash of the hotfix package — it should be "c81bd88cbf555ccfba8fc695173bf505"<br /></li><li>Extract it in the Products directory of your Zope instance</li><li>Restart Zope</li><li>Go to the 'Add-on Products' panel in the Plone Site Setup</li><li>Install the hotfix product</li></ul>
<h2>Uninstalling the hotfix</h2>
<ul><li>Remove 'PloneHotfixCVE20080164' from the Products directory of your Plone instance<br />
</li></ul>
<ul><li>Restart Zope</li></ul>
<h2>Temporary workaround</h2>
<p>If you can't upgrade your sites to the latest version of Plone yet,
there are some simple steps you can take to make sure you are not
affected by this vulnerability.</p>
<p>The most important thing to understand is that this vulnerability is
not remotely exploitable — i.e. it requires you to take a particular
action, <strong>and </strong>a targeted attack for you to be exposed. Thus, you can make sure you are not affected by this quite easily:</p>
<p>
<strong>Only log in as the administrator user when you really need to,
and log out when you are done. Do not visit untrusted web sites
(especially in other tabs of the same browser) while you are logged in
to your Plone site as an administrator. Try to limit browsing of
untrusted sites even when you are logged in as a normal user.<br /></strong></p>
<p>
As long as you do not visit other sites while operating your Plone
site, this vulnerability cannot affect you. Plone has built-in
protection against this since version 2.1 for the Plone site itself, so
you only need to worry about visiting non-Plone sites that do not
filter out malicious HTML. (But double check that you haven't manually
turned off HTML filtering in your site to allow risky HTML like forms
and Javascript).</p>
<p>If your habit is to browse your site logged in as an administrator,
we encourage you to create a normal user for this instead, and only use
the admin account when you really need to.</p>
<p>The real fix is of course to upgrade Plone to the latest release as soon as possible.</p>
<h2>For developers<br /></h2>
<ul><li>Wikipedia has an article explaining <a href="http://en.wikipedia.org/wiki/Cross-site_request_forgery">how CSRF works</a>.</li><li>Since
this type of attack is on the rise in web applications in general,
Plone now includes protection for it in its core.</li><li>See the <code>plone.protect</code> and <code>plone.keyring</code> modules for making use of this in your own applications.<br /></li></ul>
<h2>Reported incidents</h2>
<p>
No incidents of this vulnerability being exploited have been reported.</p>
<h2>References</h2>
<dl><dt>CVE </dt><dd><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0164">CVE-2008-0164</a><br /></dd></dl>
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Wichert Akkerman</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2008-05-13T17:10:00Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/cve-2007-5741">
    <title>CVE-2007-5741: Unsafe data interpreted as pickles</title>
    <link>http://plone.org/products/plone/security/advisories/cve-2007-5741</link>
    <description>This hotfix corrects a vulnerability in the statusmessages and linkintegrity modules, where unsafe network data was interpreted as python pickles. This allows an attacker to run arbitrary python code within the Zope/Plone process.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[
<p>This issue has been assigned <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5741">CVE-2007-5741</a>.</p>
<h2>Affected versions</h2>
<ul><li>Plone 2.5 up to and including 2.5.4</li><li>Plone 3.0 up to and including 3.0.2<br /></li></ul>
<p>These fixes will be included in the 2.5.5 and 3.0.3 releases, at which point this hotfix can be removed.</p>
<h2>Installing the hotfix</h2>
<p>If an updated Plone is not released by the time you read this, or you can not upgrade your Plone, you can install <a title="Plone Hotfix 20071106" href="../../../products/plone-hotfix/releases/20071106-2">Plone Hotfix 2007-11-06</a>. The hotfix can be installed as a normal Zope product:</p>
<ul><li>Extract it in the Products directory of your Zope instance</li><li>Restart Zope</li><li>Verify that the hotfix is listed in the product management page in the Zope Control Panel</li></ul>
<h2>Reported incidents</h2>
No incidents of this happening to sites in the wild have been reported.
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Wichert Akkerman</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2007-11-02T21:04:52Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/zope-xss-vulnerability-2007-03-20">
    <title>Zope XSS vulnerability, please update your sites</title>
    <link>http://plone.org/products/plone/security/advisories/zope-xss-vulnerability-2007-03-20</link>
    <description>A vulnerability has been discovered in Zope, whereby misuse of certain types of HTTP GET could lead to elevated privileges. All Zope versions up to and including 2.10.2 are affected.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>The full description along with the hotfix for Zope 2.7, 2.8, 2.9 and 2.10 is <a href="http://www.zope.org/Products/Zope/Hotfix-2007-03-20/announcement">available from the zope.org site</a>.</p>
<p>The upcoming releases of Zope will have this fix included, in the meantime, please download the hotfix for your installations. Unpack the product and restart Zope, and the vulnerability will be patched.</p>
<p><strong>You are only affected by this vulnerability if you allow untrusted users to log in to your site and create content.</strong></p>
<p><span class="discreet">This news item will be updated once a CVE number has been assigned.</span></p>
]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Alex Limi</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2007-03-21T05:08:26Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/cve-2006-4249">
    <title>Security: PlonePAS user/group fix (CVE-2006-4249)</title>
    <link>http://plone.org/products/plone/security/advisories/cve-2006-4249</link>
    <description>PlonePAS-using Plone releases (Plone 2.5 and Plone 2.5.1) has a potential vulnerability that allows a user to masquerade as a group. Please update your sites.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>This issue has been assigned <a class="generated" href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4249">CVE-2006-4249</a></p><h3>Affected versions</h3><ul><li>Plone 2.5 <br /></li><li>Plone 2.5.1</li></ul><p>Plone versions 1.0.x, 2.0.x and 2.1.x are NOT affected <b>unless</b> you have separately installed PlonePAS and have not configured a prefix property on the source_groups plugin.</p><p>This vulnerability only applies to sites which allow member registration to anonymous users.<br /></p><h3>Installing the hotfix</h3><p>If Plone 2.5.2 is not released by the time you read this, or you can not upgrade your Plone, you can install <a href="/products/plone-hotfix/releases/20061031">Plone Hotfix 2006-10-31</a>. The hotfix can be installed as a normal Zope product:</p><ul><li>Extract it in the Products directory of your Zope instance</li><li>Restart Zope</li><li>Verify that the hotfix is listed in the product management page in the Zope Control Panel</li></ul><br /><h3>Reported incidents</h3><p>No incidents of this happening to sites in the wild have been reported.<br /></p><br />]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Alex Limi</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2006-11-02T01:07:28Z</dc:date>
    <dc:type>News Item</dc:type>
  </item>


  <item rdf:about="http://plone.org/products/plone/security/advisories/cve-2006-4684">
    <title>Zope reStructuredText information disclosure (CVE-2006-4684)</title>
    <link>http://plone.org/products/plone/security/advisories/cve-2006-4684</link>
    <description>A information disclosure vulnerability has been discovered in Zope/Plone's handling of csv_table command in reStructuredText content. Any Plone sites which allows untrusted users to add/edit RestructuredText content are vulnerable to this issue and should apply the hotfix.</description>
    <content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p>This vulnerability has been assigned CVE id <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4684">CVE-2006-4684</a>.</p><br /><h2>Vulnerability details</h2>reStructuredText supports the <i>csv_table</i>
directive. This could be used to expose filesystem content from the
Zope server through the Zope and Plone webinterface.<br /><br />The fix disables the csv_table.  No Plone functionality is affected by this change.<br /><br /><h2>Affected versions</h2><p>Affected Plone versions are:</p><ul><li>Plone 2.0 up to version 2.0.5</li><li>Plone 2.1 up to version 2.1.3</li></ul>Plone 2.5 and later running on Zope 2.9 is not affected. Installers for all later release will include a fix for this problem.<br /><br />For installations that do not use the standard Plone installer please check the used Zope version:<br /><ul><li>Zope 2.7 up to version 2.7.8</li><li>Zope 2.8 up to version 2.8.8<br /></li></ul><br /><h2>Installing the hotfix</h2>This bug can be fixed by installing the <a href="http://www.zope.org/Products/Zope/Hotfix-2006-08-21/Hotfix-20060821/">Zope 20060821</a> hotfix. The hotfix can be installed as a normal Zope product:<br /><ul><li>extract it in the Products directory of your Zope instance</li><li>restart Zope</li><li>verify that Hotfix_20060821 is listed in the product management page in the Zope control panel</li></ul>]]></content:encoded>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Wichert Akkerman</dc:creator>
    <dc:rights></dc:rights>
    <dc:date>2006-10-02T12:08:50Z</dc:date>
    <dc:type>Page</dc:type>
  </item>





</rdf:RDF>

