CVE-2010-3198

Zope 2.10.0-2.10.11 and 2.11.0-2.11.6 - Denial of Service via Uncaught Exception Handling

Title source: llm
STIX 2.1

Description

ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.

References (6)

Core 6
Core References
Various Sources x_refsource_confirm
http://www.zope.org/Products/Zope/2.10.12/CHANGES.txt
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2275
Patch, Vendor Advisory mailing-list x_refsource_mlist
https://mail.zope.org/pipermail/zope-announce/2010-September/002247.html
Various Sources x_refsource_confirm
http://www.zope.org/Products/Zope/2.11.7/CHANGES.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/42939
Exploit, Patch, Vendor Advisory x_refsource_confirm
https://bugs.launchpad.net/zope2/+bug/627988

Scores

EPSS 0.0153
EPSS Percentile 72.1%

Details

Status published
Products (29)
pypi/Zope 2.10.0 - 2.10.12PyPI
pypi/Zope 2.11.0 - 2.11.7PyPI
zope/zope 2.10.0-b1
zope/zope 2.10.0-b2
zope/zope 2.10.0-c1
zope/zope 2.10.0-final
zope/zope 2.10.2
zope/zope 2.10.2-b1
zope/zope 2.10.2-final
zope/zope 2.10.3
... and 19 more
Published Sep 08, 2010
Tracked Since Feb 18, 2026