CVE-2005-3323: High severity Zope Zope vulnerability
Published Oct 27, 2005
·Updated
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
Affected Software
5 affected components
Zope Zope=2.6
Zope Zope>=2.7.0<2.7.8
Zope Zope>=2.8.0<2.8.2
Debian Debian Linux=3.1
Debian Debian Linux=3.0
Remediation
Event History
Oct 27, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3323?
CVE-2005-3323 has a medium severity rating due to its potential for remote file inclusion.
2
How do I fix CVE-2005-3323?
To fix CVE-2005-3323, upgrade Zope to version 2.7.8 or later, or to 2.8.2 or later.
3
Which versions of Zope are affected by CVE-2005-3323?
CVE-2005-3323 affects Zope versions 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2.
4
Can CVE-2005-3323 lead to data exposure?
Yes, CVE-2005-3323 can allow unauthorized file access, potentially exposing sensitive data.
5
Is there a workaround for CVE-2005-3323?
While upgrading is the recommended solution, temporarily limiting access to vulnerable include directives may serve as a workaround.