CVE-2006-3458

Zope 2.7.0-2.7.8 2.8.0-2.8.7 2.9.0-2.9.3 - Arbitrary File Read via reStructuredText Raw Command

Title source: llm
STIX 2.1

Description

Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27636
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2681
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21025
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21130
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21459
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_19_sr.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1113
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18856
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20988
Various Sources mailing-list x_refsource_mlist
http://mail.zope.org/pipermail/zope-announce/2006-July/001984.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/317-1/

Scores

EPSS 0.0042
EPSS Percentile 34.5%

Details

Status published
Products (22)
pypi/Zope2 2.7.0 - 2.7.8PyPI
zope/zope 2.7.0
zope/zope 2.7.1
zope/zope 2.7.2
zope/zope 2.7.3
zope/zope 2.7.4
zope/zope 2.7.5
zope/zope 2.7.6
zope/zope 2.7.7
zope/zope 2.7.8
... and 12 more
Published Jul 07, 2006
Tracked Since Feb 18, 2026