Release date: 2011-10-06
Updated on: 2011-10-10
Affected Systems:
Plone 4.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-3587
Plone is an open-source content management system built on the Python application server Zope and its corresponding Zope content management framework.
Plone has two security vulnerabilities, which can be exploited by malicious users to control the affected system.
1) the application is bound to the affected version of Zope;
2) another unknown error can be exploited to execute arbitrary commands.
<* Source: Alan Hoey
Link: http://plone.org/products/plone/security/advisories/20110928
Http://plone.org/products/plone-hotfix/releases/20110928
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Plone
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://plone.org/products/plone/security/