CVE-2006-3458

NameCVE-2006-3458
DescriptionZope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1113
Debian Bugs377277, 377285, 377286

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zope2.7sourcesarge2.7.5-2sarge2DSA-1113
zope2.7source(unstable)(unfixed)medium377285
zope2.8source(unstable)2.8.7-2medium377277
zope2.9source(unstable)2.9.3-3medium377286

Search for package or bug name: Reporting problems