[Zope-Checkins] SVN: Zope/hotfixes/Products.Zope_Hotfix_20111024/ Hotfix for vulnerability reported today.

2011-10-24 Thread Tres Seaver
Log message for revision 123147: Hotfix for vulnerability reported today. Changed: A Zope/hotfixes/Products.Zope_Hotfix_20111024/ A Zope/hotfixes/Products.Zope_Hotfix_20111024/tags/ A Zope/hotfixes/Products.Zope_Hotfix_20111024/trunk/ -=-

[Zope-Checkins] SVN: Zope/hotfixes/Products.Zope_Hotfix_20111024/trunk/ Add hotfix for vulnerability reported today.

2011-10-24 Thread Tres Seaver
Log message for revision 123148: Add hotfix for vulnerability reported today. Changed: A Zope/hotfixes/Products.Zope_Hotfix_20111024/trunk/CHANGES.txt A Zope/hotfixes/Products.Zope_Hotfix_20111024/trunk/Products/ A

[Zope-Checkins] SVN: Zope/hotfixes/Products.Zope_Hotfix_20111024/tags/1.0/ Tag hotfix for vulnerability reported today.

2011-10-24 Thread Tres Seaver
Log message for revision 123149: Tag hotfix for vulnerability reported today. Changed: A Zope/hotfixes/Products.Zope_Hotfix_20111024/tags/1.0/ -=- ___ Zope-Checkins maillist - Zope-Checkins@zope.org

[Zope-Checkins] SVN: Zope/branches/2.12/ Fix serious authentication vulnerability in stock configuration.

2011-10-24 Thread Tres Seaver
Log message for revision 123150: Fix serious authentication vulnerability in stock configuration. Changed: U Zope/branches/2.12/doc/CHANGES.rst U Zope/branches/2.12/src/AccessControl/User.py -=- Modified: Zope/branches/2.12/doc/CHANGES.rst

[Zope-Checkins] SVN: Zope/branches/2.12/src/AccessControl/tests/testUser.py Add a unittest for today's fix.

2011-10-24 Thread Tres Seaver
Log message for revision 123151: Add a unittest for today's fix. Changed: U Zope/branches/2.12/src/AccessControl/tests/testUser.py -=- Modified: Zope/branches/2.12/src/AccessControl/tests/testUser.py === ---

[Zope-Checkins] SVN: Zope/branches/2.13/ Fix serious authentication vulnerability in stock configuration.

2011-10-24 Thread Tres Seaver
Log message for revision 123152: Fix serious authentication vulnerability in stock configuration. Changed: U Zope/branches/2.13/doc/CHANGES.rst U Zope/branches/2.13/src/OFS/tests/test_userfolder.py U Zope/branches/2.13/src/OFS/userfolder.py -=- Modified:

[Zope-Checkins] SVN: Zope/trunk/ Fix serious authentication vulnerability in stock configuration.

2011-10-24 Thread Tres Seaver
Log message for revision 123153: Fix serious authentication vulnerability in stock configuration. Changed: U Zope/trunk/doc/CHANGES.rst U Zope/trunk/src/OFS/tests/test_userfolder.py U Zope/trunk/src/OFS/userfolder.py -=- Modified: Zope/trunk/doc/CHANGES.rst

Re: [Zope-dev] zope-tests - FAILED: 21, OK: 31

2011-10-24 Thread Brian Sutherland
On Thu, Oct 20, 2011 at 11:58:09AM -0400, Tres Seaver wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [1]FAILED ZTK 1.0dev / Python2.4.6 Linux 64bit https://mail.zope.org/pipermail/zope-tests/2011-October/051353.html [2]FAILED ZTK 1.0dev / Python2.5.5 Linux 64bit

Re: [Zope-dev] zope-tests - FAILED: 21, OK: 31

2011-10-24 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/24/2011 07:24 AM, Brian Sutherland wrote: On Thu, Oct 20, 2011 at 11:58:09AM -0400, Tres Seaver wrote: Syntax errors due to Py3k compatibility changes in 'zope.schema'. The ZTK 1.1dev checkouts pull in the trunk of 'zope.schema', which is

Re: [Zope-dev] zope-tests - FAILED: 21, OK: 31

2011-10-24 Thread Hanno Schlichting
On Mon, Oct 24, 2011 at 5:08 PM, Tres Seaver tsea...@palladion.com wrote: I also prefer that we drop 2.5 compatibility on the ZTK trunk.  The 2.5.6 release page says[1]:  This release is most likely the final release of Python 2.5; under  the current release policy, no security issues in

Re: [Zope-dev] Change in webmaster position

2011-10-24 Thread Simon Michael
Thanks for all the hard work Michael! Best, -Simon ___ Zope-Dev maillist - Zope-Dev@zope.org https://mail.zope.org/mailman/listinfo/zope-dev ** No cross posts or HTML encoding! ** (Related lists -

[Zope-dev] new wiki.zope.org editor login

2011-10-24 Thread Simon Michael
Hey all.. the shared login for wiki.zope.org editing has been discovered by a spammer, so I've changed the password. The login is now zope, edit0r. See the message below for more context. Best, -Simon In 2011/05 I wrote: Dear all, edit spam across the wiki.zope.org wikis, gradually

[Zope-dev] Hotfix for security vulnerability

2011-10-24 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On behalf of the Zope security response team, I would like to announce the availability of a hotfix for a vulnerability inadvertently published earlier today. 'Products.Zope_Hotfix_20111024' README == Overview -

[Zope-dev] zope-tests - FAILED: 11, OK: 40

2011-10-24 Thread Zope tests summarizer
This is the summary for test reports received on the zope-tests list between 2011-10-23 00:00:00 UTC and 2011-10-24 00:00:00 UTC: See the footnotes for test reports of unsuccessful builds. An up-to date view of the builders is also available in our buildbot documentation:

[Zope] serious security hole in manage users / Manage users permissions?

2011-10-24 Thread Niels Dettenbach
Dear Zope 2.12/.13 (4.0) devels, as far as i can see i may have found a serious security hole within Zope 2.12 / 2.13 (4.0 not tested yet) - I'm still investigate here further... problem: == Even on fresh Installs of Zope and fresh created instances on it anonymous / remote users able to

Re: [Zope] serious security hole in manage users / Manage users permissions?

2011-10-24 Thread Laurence Rowe
Potential security issues should not be discussed on public mailing lists but submitted to security-respo...@zope.org. Please submit the full information to that address and do not follow up further on this list. Laurence On 24 October 2011 15:05, Niels Dettenbach n...@syndicat.com wrote: Dear

Re: [Zope] serious security hole in manage users / Manage userspermissions?

2011-10-24 Thread Jaroslav Lukesh
2.10.13 is not affected in direct link nor acquired link. ___ Zope maillist - Zope@zope.org https://mail.zope.org/mailman/listinfo/zope ** No cross posts or HTML encoding! ** (Related lists - https://mail.zope.org/mailman/listinfo/zope-announce

[Zope] Manipulating images in Zope/Python

2011-10-24 Thread Brian Sullivan
I am looking for strategy to programmatically create a customized printable certificate of completion for our Learning Delivery System courses (the system is Zope/Python based). My current plan is to use the Python Imaging Library to create the image (probably by overlaying some text on a stock

[Zope] Hotfix for security vulnerability

2011-10-24 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On behalf of the Zope security response team, I would like to announce the availability of a hotfix for a vulnerability inadvertently published earlier today. 'Products.Zope_Hotfix_20111024' README == Overview -

[Zope-CMF] cmf-tests - OK: 4

2011-10-24 Thread CMF tests summarizer
This is the summary for test reports received on the cmf-tests list between 2011-10-23 00:00:00 UTC and 2011-10-24 00:00:00 UTC: See the footnotes for test reports of unsuccessful builds. An up-to date view of the builders is also available in our buildbot documentation: