Welcome, guest | Sign In | My Account | Store | Cart

Notice! PyPM is being replaced with the ActiveState Platform, which enhances PyPM’s build and deploy capabilities. Create your free Platform account to download ActivePython or customize Python with the packages you require and get automatic updates.

Download
ActivePython
INSTALL>
pypm install products.plonehotfix20110928

How to install Products.PloneHotfix20110928

  1. Download and install ActivePython
  2. Open Command Prompt
  3. Type pypm install products.plonehotfix20110928
 Python 2.7Python 3.2Python 3.3
Windows (32-bit)
1.1 Available View build log
Windows (64-bit)
1.1 Available View build log
Mac OS X (10.5+)
1.1 Available View build log
Linux (32-bit)
1.1 Available View build log
Linux (64-bit)
1.1 Available View build log
 
License
GPL
Dependencies
Lastest release
version 1.1 on Oct 5th, 2011

This hotfix fixes the following vulnerabilities:

  • A vulnerability in CMFEditions where KwAsAttributes classes were publishable, exposing sub-objects to anonymous access. This vulnerability is found in CMFEditions 2.0a1 and up. CMFEditions 1.x and before are not vulnerable.

  • Zope vulnerability CVE 2011-3587. This vulnerability is found in Zope 2.12.x and 2.13.x. Zope 2.11 and before are not vulnerable.

    This Plone Hotfix applies the same fix as Products.Zope_Hotfix_CVE_2011_3587 and can co-exist with that patch.

This hotfix is supported on Plone 4.0 - 4.0.9, 4.1 and 4.2. Older versions of Plone (3.3.x and below) are not affected by the vulnerabilities and are not supported by this patch.

The fixes included here will be incorporated into subsequent releases of Plone, so Plone 4.0.10, 4.1.1, 4.2a3 and greater should not require this hotfix.

Installation

Installation instructions can be found at http://plone.org/products/plone-hotfix/releases/20110928

Changelog

1.1 (2011-10-04)
  • Fix URLs in the readme and setup.py. [mj]
1.0 (2011-10-04)
  • Initial release [Plone security team]

Subscribe to package updates

Last updated Oct 5th, 2011

Download Stats

Last month:1

What does the lock icon mean?

Builds marked with a lock icon are only available via PyPM to users with a current ActivePython Business Edition subscription.

Need custom builds or support?

ActivePython Enterprise Edition guarantees priority access to technical support, indemnification, expert consulting and quality-assured language builds.

Plan on re-distributing ActivePython?

Get re-distribution rights and eliminate legal risks with ActivePython OEM Edition.