9 days ago by gmane.comp.web.zope.announce
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Overview
========
In response to the cross-site scripting vulnerability in Zope2 reported as
'CVE 2010-1104'[1], the Zope security response team announces the
availablility of a hotfix product (for Zope < 2.12), and new releases for
the Zope 2.12 and 2.13 lines:
Hotfix: http://pypi.python.org/pypi/Products.Zope_Hotfix_CVE_2010_1104
Zope 2.12.22: http://pypi.python.org/pypi/Zope2/2.12.22
Zope 2.13.12: http://pypi.python.org/pypi/Zope2/2.13.12
WARNING: Zope < 2.12 is no longer officially supported, and may have
other unpatched vulnerabilities. You are encouraged to
upgrade to a supported Zope 2.
Installing the Hotfix
=====================
The hotfix has been tested with Zope instances using Zope 2.8.x - 2.11.x.
Users of Zope 2.12.x and 2.13.x should instead update to the latest
corresponding minor revision, which already includes this fix.
Download the tarball from the PyPI page:
http://pypi.python.org/pypi/Products.Zope_Hotfix_CVE