Re: [Zope-dev] Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

2013-01-27 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/27/2013 11:55 AM, David Glick (Plone) wrote: > On 1/27/13 6:00 PM, Tres Seaver wrote: >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >> >> On 01/27/2013 08:49 AM, Julien Cristau wrote: >>> On Mon, Nov 26, 2012 at 18:53:58 +0900, Arnaud Fontain

Re: [Zope-dev] Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

2013-01-27 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/27/2013 08:49 AM, Julien Cristau wrote: > On Mon, Nov 26, 2012 at 18:53:58 +0900, Arnaud Fontaine wrote: > >> Tres Seaver writes: >> * CVE-2012-5505 (zope.traversing: atat.py) http://plone.org/products/plone/security/advisories/2012

Re: [Zope-dev] Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

2012-11-26 Thread Arnaud Fontaine
Hello, Tres Seaver writes: >> version 2.12.21: * LP #1079238 fixes CVE 2012-5489. >> >> According to the upstream changelog, LP #1047318 seems to fix a >> security bug, but I could not find it in zope2 launchpad nor anywhere >> else. > > That bug was still in "Private Security" state: I

Re: [Zope-dev] Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

2012-11-25 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/24/2012 09:07 PM, Arnaud Fontaine wrote: > Luciano Bello writes: > >> Hi, please see : http://seclists.org/oss-sec/2012/q4/249 >> >> Can you confirm if any of the Debian packages are affected? > > As far as I could find (not clear in the ups

Re: [Zope-dev] Bug#692899: zope2.12: [CVE-2012-5485 to 5508] Multiple vectors corrected within 20121106 fix

2012-11-24 Thread Arnaud Fontaine
Hello, Luciano Bello writes: > Hi, please see : http://seclists.org/oss-sec/2012/q4/249 > > Can you confirm if any of the Debian packages are affected? As far as I could find (not clear in the upstream changelog): version 2.12.26: * LP #1071067 fixes CVE 2012-5507, CVE 2012-5508. * LP #930