CVE-2006-3458
Zope 2.7.0-2.7.8 2.8.0-2.8.7 2.9.0-2.9.3 - Arbitrary File Read via reStructuredText Raw Command
Title source: llmDescription
Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
References (12)
Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27636
Various Sources x_refsource_confirm
http://www.zope.org/Products/Zope/Hotfix-2006-07-05/Hotfix-20060705/README.txt
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2681
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21025
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21130
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21459
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_19_sr.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1113
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/18856
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20988
Various Sources mailing-list
x_refsource_mlist
http://mail.zope.org/pipermail/zope-announce/2006-July/001984.html
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/317-1/
Scores
EPSS
0.0042
EPSS Percentile
34.5%
Details
Status
published
Products (22)
pypi/Zope2
2.7.0 - 2.7.8PyPI
zope/zope
2.7.0
zope/zope
2.7.1
zope/zope
2.7.2
zope/zope
2.7.3
zope/zope
2.7.4
zope/zope
2.7.5
zope/zope
2.7.6
zope/zope
2.7.7
zope/zope
2.7.8
... and 12 more
Published
Jul 07, 2006
Tracked Since
Feb 18, 2026