CVE-2009-0668: Code Injection
Published Aug 7, 2009
·Updated
Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to execute arbitrary Python code via vectors involving the ZEO network protocol.
Affected Software
18 affected componentsFixes available
pip/ZODB3<3.8.2
3.8.2
Zope ZODB<=3.8.1
Zope ZODB=2.8.11
Zope ZODB=2.9.11
Zope ZODB=2.10.9
Zope ZODB=2.11.4
Zope ZODB=3.1
Zope ZODB=3.1.1
Zope ZODB=3.2
Zope ZODB=3.2.4
Zope ZODB=3.3
Zope ZODB=3.3.3
Zope ZODB=3.4
Zope ZODB=3.4.1
Zope ZODB=3.5
Zope ZODB=3.6
Zope ZODB=3.7
Zope ZODB=3.8.0
Event History
Aug 7, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 2, 2022
Advisory Published
via GitHub·03:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2009-0668?
CVE-2009-0668 has a high severity rating due to its potential to allow remote attackers to execute arbitrary Python code.
2
How do I fix CVE-2009-0668?
To fix CVE-2009-0668, upgrade to ZODB version 3.8.2 or later.
3
What versions are affected by CVE-2009-0668?
CVE-2009-0668 affects ZODB versions prior to 3.8.2, including versions 2.8.11 to 3.8.1.
4
What does CVE-2009-0668 exploit?
CVE-2009-0668 exploits a vulnerability in the ZEO network protocol when certain database sharing is enabled.
5
Is there a workaround for CVE-2009-0668?
A recommended workaround for CVE-2009-0668 is to disable database sharing in ZEO until the software is upgraded.