Skip to content. | Skip to navigation


Encryptec Limited Online

 Last updated Thursday, 08 Nov 2007 18:52
Sections
Document Actions

Plone System Upgrade

We've just run an emergency upgrade against Plone 2.5.2 instances

This was as a result of a critical security vulnerability issued just now by the Plone Foundation. We've checked a number of sites and there seem to be no ill effects, however if you spot a problem with your site, please let us know and we'll investigate asap.

(the upgrade should just be security fixes, there have been no major changes)

  • We are now running Plone version 2.5.4 rev 2.

Issue Details

CVE-2007-5741: Unsafe data interpreted as pickles

This upgrade corrects a vulnerability in the statusmessages and linkintegrity modules, where unsafe network data was interpreted as python pickles. This allows an attacker to run arbitrary python code within the Zope/Plone process.

This issue has been assigned CVE-2007-5741.

Affected versions

  • Plone 2.5 up to and including 2.5.4
  • Plone 3.0 up to and including 3.0.2

These fixes are included in the 2.5.5 and 3.0.3 releases, at which point this hotfix can be removed.

Installing the hotfix

If an updated Plone is not released by the time you read this, or you can not upgrade your Plone, you can install Plone Hotifix 2007-11-06. The hotfix can be installed as a normal Zope product:

  • Extract it in the Products directory of your Zope instance
  • Restart Zope
  • Verify that the hotfix is listed in the product management page in the Zope Control Panel

Reported incidents

No incidents of this happening to sites in the wild have been reported.

Plone.ORG News
Plone Conference 2008 Sessions Announced! 06 Aug 2008
Plone Conference 2008: Early Bird Registration Extended 01 Aug 2008
plone members integration with zforum 28 Jul 2008
Plone Tune-Up Rally - Help Make Plone Even Better! 23 Jul 2008
More news…
 
printer cartridges
Don't settle for any old supplier. Get the best ink for the best price. See our great range of printer cartridges at competitive prices.
Web Site Designer
Let our web site designers create your website. Then use our simple-to-use Content Management System to update it as needed!
Remote Support
It doesn't matter how often you call! Our price for IT service is fixed. Go to Connect.co.uk.
Crm Software Solutions...
Customer relationship management software can be found by clicking the above link.
HP Compaq Laptops
Offer rock-solid security, uncompromising reliability and ease of use, HP has got it all covered.
Canon Ink Cartridges
Buy all Canon ink cartridges at this handy site.
Dedicated Server
Check out the price of dedicated servers this company offers. Click on the link above and see.
Samsung Laptop
Samsung Laptop at lowest prices here!
Online Data Storage
Check out this sites options for online storage...