You are not logged in Log in Join
You are here: Home » Download Zope Products » Zope » Hotfix_2001-07-25 » README.txt

Log in
Name

Password

 

README.txt

File details
Size
1 K
File type
text/plain

File contents

Hotfix_2001-07-25

  This is a "hotfix" product. Hotfix products can be installed to 
  incorporate modifications to Zope at runtime without requiring 
  an immediate installation upgrade. Hotfix products are installed 
  just as you would install any other Zope product.

  This hotfix addresses a potential denial-of-service vulnerability
  in applications that use the Python cgi module (cgi.py) for parsing
  of "multipart" Web form data (Zope uses this functionality
  internally).

  More detailed information is available in the Python bug tracker at
  SourceForge:

  http://sourceforge.net/tracker/?group_id=5470&atid=105470&func=detail&aid=443120


  While we are not aware of any instances of abuse of this
  vulnerability, we *highly* recommend that any Zope site running versions
  of Zope up to and including 2.4.0  have this hotfix product installed 
  to mitigate this issue. (Zope 2.4.1 will not require the
  installation of a separate hotfix).