First published: Thu Oct 27 2005(Updated: )
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zope ZODB | >=2.7.0<2.7.8 | |
Zope ZODB | >=2.8.0<2.8.2 | |
Zope ZODB | =2.6 | |
Debian | =3.0 | |
Debian | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3323 has a medium severity rating due to its potential for remote file inclusion.
To fix CVE-2005-3323, upgrade Zope to version 2.7.8 or later, or to 2.8.2 or later.
CVE-2005-3323 affects Zope versions 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2.
Yes, CVE-2005-3323 can allow unauthorized file access, potentially exposing sensitive data.
While upgrading is the recommended solution, temporarily limiting access to vulnerable include directives may serve as a workaround.