PYSEC-2006-8
Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.
Details
The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/zope2
Introduced in:
0No fixed version published yet for zope2 (pip). Pin to a known-safe version or switch to an alternative.
References
- http://mail.zope.org/pipermail/zope-announce/2006-August/002005.html[WEB]
- http://www.zope.org/Products/Zope/Hotfix-2006-08-21/Hotfix-20060821/README.txt[FIX]
- http://www.debian.org/security/2006/dsa-1176[FIX]
- http://www.debian.org/security/2006/dsa-1176[ADVISORY]
- http://secunia.com/advisories/21947[FIX]
- http://secunia.com/advisories/21947[ADVISORY]
- http://secunia.com/advisories/21953[FIX]
- http://secunia.com/advisories/21953[ADVISORY]
- http://www.securityfocus.com/bid/20022[WEB]
- http://www.vupen.com/english/advisories/2006/3653[ADVISORY]
- https://github.com/advisories/GHSA-hm8g-jxjj-gfm3[ADVISORY]