Zope PythonScript 'PythonScriptss'拒绝服务漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1116727 漏洞类型 资源管理错误
发布时间 2008-11-12 更新时间 2008-11-18
CVE编号 CVE-2008-5102 CNNVD-ID CNNVD-200811-253
漏洞平台 Multiple CVSS评分 4.0
|漏洞来源
https://www.exploit-db.com/exploits/32581
https://www.securityfocus.com/bid/32267
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200811-253
|漏洞详情
当在Conga和其他产品中使用时,Zope中的PythonScriptss允许远程认证用户借助特定的(1)raise或(2)输入语句,来引起拒绝服务攻击(资源耗竭或应用程序中止)。
|漏洞EXP
source: http://www.securityfocus.com/bid/32267/info

Zope is prone to multiple remote denial-of-service vulnerabilities.

Remote attackers can exploit this issue to cause the Zope server to halt or to consume excessive server resources, resulting in denial-of-service conditions.

These issues affect Zope 2.7.0 through 2.11.2. 

To halt the application:
raise SystemExit

To consume excessive resources:
return 'foo'.encode('test.testall')
|受影响的产品
Zope Zope 2.11.2 Zope Zope 2.10.2 Zope Zope 2.10.1 Zope Zope 2.9.3 Zope Zope 2.9.2 Zope Zope 2.9.1 Zope Zope 2.9 Zope Zope 2.8.8
|参考资料

来源:www.zope.org
链接:http://www.zope.org/Products/Zope/Hotfix-2008-08-12/Hotfix_20080812-1.1.0.tar.gz
来源:bugs.launchpad.net
链接:https://bugs.launchpad.net/zope2/+bug/257276
来源:bugs.launchpad.net
链接:https://bugs.launchpad.net/zope2/+bug/257269
来源:www.zope.org
链接:http://www.zope.org/Products/Zope/Hotfix-2008-08-12/README.txt
来源:VUPEN
名称:ADV-2008-2418
链接:http://www.vupen.com/english/advisories/2008/2418
来源:MLIST
名称:[oss-security]20081112CVERequest-Zope2-PythonScriptslocalDoS
链接:http://openwall.com/lists/oss-security/2008/11/12/2
来源:MLIST
名称:[Zope]20080812Script(Python)insecure?
链接:http://mail.zope.org/pipermail/zope/2008-August/174025.html
来源:bugs.gentoo.org
链接:http://bugs.gentoo.org/show_bug.cgi?id=246411