First published: Mon Nov 17 2008(Updated: )
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zope ZODB | =2.0.0b6 | |
Zope ZODB | =2.7.3-final | |
Zope ZODB | =2.4.0 | |
Zope ZODB | =2.2.0b2 | |
Zope ZODB | =2.7.3-b2 | |
Zope ZODB | =2.7.0-final | |
Zope ZODB | =2.2.1 | |
Zope ZODB | =2.7.4-b2 | |
Zope ZODB | =2.3.1 | |
Zope ZODB | =2.8.8 | |
Zope ZODB | =2.2.0b4 | |
Zope ZODB | =1.10.3 | |
Zope ZODB | =2.7.4-c1 | |
Zope ZODB | =2.10.5 | |
Zope ZODB | =2.4.4b1 | |
Zope ZODB | =2.8.9.1 | |
Zope ZODB | =2.2.0 | |
Zope ZODB | =2.1.2 | |
Zope ZODB | =2.0.0b5 | |
Zope ZODB | =2.3.0b3 | |
Zope ZODB | =2.7.0-b2 | |
Zope ZODB | =1.10.4 | |
Zope ZODB | =2.10.4-final | |
Zope ZODB | =2.6.4-rc2 | |
Zope ZODB | =2.9.0-b2 | |
Zope ZODB | =2.11.1 | |
Zope ZODB | =2.3.2 | |
Zope ZODB | =2.5.1b1 | |
Zope ZODB | =2.5.0 | |
Zope ZODB | =2.4.0b1 | |
Zope ZODB | =2.4.1 | |
Zope ZODB | =2.10.7 | |
Zope ZODB | =2.1.6 | |
Zope ZODB | =2.4.4-upgrade | |
Zope ZODB | =2.0.1 | |
Zope ZODB | =2.9.2 | |
Zope ZODB | =2.7.2-c1 | |
Zope ZODB | =2.8.0-b2 | |
Zope ZODB | =2.1.0b1 | |
Zope ZODB | =2.3.2b1 | |
Zope ZODB | =2.4.0b3 | |
Zope ZODB | =2.3.1b3 | |
Zope ZODB | =2.1.5 | |
Zope ZODB | =2.3.1b2 | |
Zope ZODB | =2.1.0b2 | |
Zope ZODB | =2.10.0-b1 | |
Zope ZODB | =2.7.0-c2 | |
Zope ZODB | =2.6.2.b3 | |
Zope ZODB | <=2.11.2 | |
Zope ZODB | =2.0.0 | |
Zope ZODB | =2.7.5-b1 | |
Zope ZODB | =2.3.0b2 | |
Zope ZODB | =2.7.6-final | |
Zope ZODB | =2.4.1b1 | |
Zope ZODB | =2.7.6-b1 | |
Zope ZODB | =2.9.4 | |
Zope ZODB | =2.6.0 | |
Zope ZODB | =2.9.5 | |
Zope ZODB | =2.0.0a4 | |
Zope ZODB | =2.2.1b1 | |
Zope ZODB | =2.7.7-final | |
Zope ZODB | =2.8.0-a1 | |
Zope ZODB | =2.7.1-final | |
Zope ZODB | =2.6.2 | |
Zope ZODB | =2.2.4 | |
Zope ZODB | =2.4.0a1 | |
Zope ZODB | =2.6.2.b4 | |
Zope ZODB | =2.8.1-final | |
Zope ZODB | =2.9.1 | |
Zope ZODB | =2.4.3-upgrade | |
Zope ZODB | =2.10.0-c1 | |
Zope ZODB | =2.8.9 | |
Zope ZODB | =2.7.4-final | |
Zope ZODB | =2.4.2 | |
Zope ZODB | =2.11.0 | |
Zope ZODB | =2.8.0-final | |
Zope ZODB | =2.8.0-a2 | |
Zope ZODB | =2.7.5-c1 | |
Zope ZODB | =2.4.3 | |
Zope ZODB | =2.10.2-b1 | |
Zope ZODB | =2.5.1-upgrade | |
Zope ZODB | =2.8.5 | |
Zope ZODB | =2.8.2 | |
Zope ZODB | =2.2.2 | |
Zope ZODB | =2.10.3-final | |
Zope ZODB | =2.1.3 | |
Zope ZODB | =2.8.6 | |
Zope ZODB | =2.7.7-b1 | |
Zope ZODB | =2.4.4 | |
Zope ZODB | =2.3.3b1 | |
Zope ZODB | =2.2.5b1 | |
Zope ZODB | =2.5.1b2 | |
Zope ZODB | =2.8.0-b1 | |
Zope ZODB | =2.6.2.b1 | |
Zope ZODB | =2.2.0b1 | |
Zope ZODB | =2.8.1-b1 | |
Zope ZODB | =2.2.4b1 | |
Zope ZODB | =2.2.0b3 | |
Zope ZODB | =2.6.0b1 | |
Zope ZODB | =2.9.7 | |
Zope ZODB | =2.7.9 | |
Zope ZODB | =2.3.2b2 | |
Zope ZODB | =2.9.6 | |
Zope ZODB | =2.10.0-b2 | |
Zope ZODB | =2.7.0-b1 | |
Zope ZODB | =2.7.0-a1 | |
Zope ZODB | =2.1.0 | |
Zope ZODB | =2.9.10 | |
Zope ZODB | =2.2.5 | |
Zope ZODB | =2.7.5-final | |
Zope ZODB | =2.3.0a2 | |
Zope ZODB | =2.7.0-b4 | |
Zope ZODB | =2.5.0b1 | |
Zope ZODB | =2.6.2.b6 | |
Zope ZODB | =2.4.0b2 | |
Zope ZODB | =2.7.1-b2 | |
Zope ZODB | =2.8.3 | |
Zope ZODB | =2.6.3 | |
Zope ZODB | =2.4.3b1 | |
Zope ZODB | =2.4.2b1 | |
Zope ZODB | =2.7.4-b1 | |
Zope ZODB | =2.6.1.b1 | |
Zope ZODB | =2.7.0-b3 | |
Zope ZODB | =2.1.4 | |
Zope ZODB | =2.6.2.b2 | |
Zope ZODB | =2.7.4-c2 | |
Zope ZODB | =2.9.3 | |
Zope ZODB | =2.0.0b4 | |
Zope ZODB | =2.7.3-b1 | |
Zope ZODB | =2.1.1 | |
Zope ZODB | =2.3.0 | |
Zope ZODB | =2.6.4 | |
Zope ZODB | =2.6.4-rc1 | |
Zope ZODB | =2.8.4 | |
Zope ZODB | =2.7.8 | |
Zope ZODB | =2.6.2.b5 | |
Zope ZODB | =2.5.0a2 | |
Zope ZODB | =2.3.0b1 | |
Zope ZODB | =2.10.6 | |
Zope ZODB | =2.9.0-b1 | |
Zope ZODB | =2.3.3 | |
Zope ZODB | =2.6.1-upgrade | |
Zope ZODB | =2.3.1b1 | |
Zope ZODB | =2.10.0-final | |
Zope ZODB | =2.9.0-final | |
Zope ZODB | =2.5.1 | |
Zope ZODB | =2.7.1-b1 | |
Zope ZODB | =2.10.2-final | |
Zope ZODB | =2.2.0a1 | |
Zope ZODB | =2.6.0b2 | |
Zope ZODB | =2.5.0a1 | |
Zope ZODB | =2.6.0a1 | |
Zope ZODB | =2.8.10 | |
Zope ZODB | =2.3.0a1 | |
Zope ZODB | =2.8.7 | |
Zope ZODB | =2.6.1 | |
Zope ZODB | =2.9.8 | |
Zope ZODB | =2.7.0-c1 | |
Zope ZODB | =2.7.2-final | |
Zope ZODB | =2.7.6-b2 | |
Zope ZODB | =2.9.9 | |
Zope ZODB | =2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5102 has been classified as a severity level that can lead to denial of service through resource consumption.
To fix CVE-2008-5102, you should upgrade to Zope version 2.11.3 or later, which addresses this vulnerability.
Affected versions of Zope include 2.11.2 and earlier versions, specifically all versions up to 2.11.2.
The potential impacts of CVE-2008-5102 include application halting or significant resource consumption, leading to denial of service.
Yes, CVE-2008-5102 allows remote authenticated users to exploit the vulnerability.