First published: Tue Jul 23 2002(Updated: )
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/zope | >=2.5.0<2.5.1b2 | 2.5.1b2 |
pip/zope | >=2.0.0<2.4.4b2 | 2.4.4b2 |
Zope ZODB | <=2.5.1b1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0687 has a high severity level due to its potential to cause a denial of service by allowing untrusted users to shut down the Zope server.
To fix CVE-2002-0687, upgrade Zope to version 2.5.1b2 or later, or to version 2.4.4b2 if on an earlier version.
Zope versions 2.0 through 2.5.1b1 are affected by CVE-2002-0687.
CVE-2002-0687 facilitates a denial of service attack by enabling untrusted users to shut down the Zope server.
Yes, the patch for CVE-2002-0687 is included in the updates to Zope versions 2.5.1b2 and 2.4.4b2.