Re: [Zope-CMF] CMF security patches in Products.PloneHotfix20121106

2012-11-15 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/13/2012 05:39 AM, johannes raggam wrote: > since most users are on the Zope mailing list (2323 users), i think > it's better to post there (and on Zope-dev). > > https://mail.zope.org/mailman/listinfo/zope > > johannes > > On 11/09/2012 08:45

Re: [Zope-CMF] CMF security patches in Products.PloneHotfix20121106

2012-11-13 Thread johannes raggam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 since most users are on the Zope mailing list (2323 users), i think it's better to post there (and on Zope-dev). https://mail.zope.org/mailman/listinfo/zope johannes On 11/09/2012 08:45 PM, David Glick (Plone) wrote: > On 11/9/12 11:33 AM, Charlie C

Re: [Zope-CMF] CMF security patches in Products.PloneHotfix20121106

2012-11-09 Thread David Glick (Plone)
On 11/9/12 11:33 AM, Charlie Clark wrote: Am 09.11.2012, 20:29 Uhr, schrieb David Glick (Plone) : We should have informed you earlier. There are a lot of tasks associated with preparing a hotfix (and this one in particular covered many vulnerabilities), and it got missed. I apologize. In the

Re: [Zope-CMF] CMF security patches in Products.PloneHotfix20121106

2012-11-09 Thread Charlie Clark
Am 09.11.2012, 20:29 Uhr, schrieb David Glick (Plone) : We should have informed you earlier. There are a lot of tasks associated with preparing a hotfix (and this one in particular covered many vulnerabilities), and it got missed. I apologize. In the future, what's the best place to report

Re: [Zope-CMF] CMF security patches in Products.PloneHotfix20121106

2012-11-09 Thread David Glick (Plone)
On 11/9/12 11:23 AM, Charlie Clark wrote: Am 09.11.2012, 17:02 Uhr, schrieb Jens Vagelpohl : Hi all, I don't recall any information being provided to the CMF developers about CMF fixes in the most recent Plone Hotfix: http://plone.org/products/plone-hotfix/releases/20121106 For example, th

Re: [Zope-CMF] CMF security patches in Products.PloneHotfix20121106

2012-11-09 Thread Charlie Clark
Am 09.11.2012, 17:02 Uhr, schrieb Jens Vagelpohl : Hi all, I don't recall any information being provided to the CMF developers about CMF fixes in the most recent Plone Hotfix: http://plone.org/products/plone-hotfix/releases/20121106 For example, there's a monkey patch to make sure getToolB

[Zope-CMF] CMF security patches in Products.PloneHotfix20121106

2012-11-09 Thread Jens Vagelpohl
Hi all, I don't recall any information being provided to the CMF developers about CMF fixes in the most recent Plone Hotfix: http://plone.org/products/plone-hotfix/releases/20121106 For example, there's a monkey patch to make sure getToolByName only returns valid tool objects and nothing else,