[Zope-Annce] SECURITY ALERT: Hotfix for dtml format method checking

Brian Lloyd brian.lloyd@zope.com
Mon, 1 Oct 2001 17:31:31 -0400


Hello all,

  Shane Hathaway recently identified a potential security issue in 
  Zope that could affect sites that let untrusted users write DTML 
  code. The issue affects Zope versions 2.2.0 through 2.4.1.

  The issue involves the "fmt" attribute of dtml-var tags.  Without
  this correction, Zope does not check security access to methods
  invoked through "fmt".  This issue could allow partially trusted
  users with enough knowledge of Zope to call, in a limited way,
  methods they would not otherwise be allowed to access.

  We highly recommend that any Zope site running Zope 2.2.0 through Zope
  2.4.1 have this hotfix product installed to mitigate the issue. Zope
  2.4.2 will contain a fix for the issue, at which time the hotfix can
  be removed.

  http://www.zope.org/Products/Zope/Hotfix_2001-09-28/README.txt

  http://www.zope.org/Products/Zope/Hotfix_2001-09-28/Hotfix_2001-09-28.tgz


Brian Lloyd        brian@zope.com
Software Engineer  540.361.1716       
Zope Corporation   http://www.zope.com