CVE-2010-3198: High severity zope zodb vulnerability
Published Sep 8, 2010
·Updated
ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.
Affected Software
29 affected componentsFixes available
pip/Zope>=2.11.0<2.11.7
2.11.7
pip/Zope>=2.10.0<2.10.12
2.10.12
Zope Zope=2.10.0-b1
Zope Zope=2.10.0-b2
Zope Zope=2.10.0-c1
Zope Zope=2.10.0-final
Zope Zope=2.10.2
Zope Zope=2.10.2-b1
Zope Zope=2.10.2-final
Zope Zope=2.10.3
Zope Zope=2.10.3-final
Zope Zope=2.10.4-final
Zope Zope=2.10.5
Zope Zope=2.10.6
Zope Zope=2.10.7
Zope Zope=2.10.8
Zope Zope=2.10.9
Zope Zope=2.10.10
Zope Zope=2.10.11
Zope Zope=2.11.0
Zope Zope=2.11.0a1
Zope Zope=2.11.0b1
Zope Zope=2.11.0c1
Zope Zope=2.11.1
Zope Zope=2.11.2
Zope Zope=2.11.3
Zope Zope=2.11.4
Zope Zope=2.11.5
Zope Zope=2.11.6
Remediation
Patch Available
Event History
Sep 8, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·05:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-3198?
CVE-2010-3198 is classified as a denial of service vulnerability that can crash worker threads of ZServer in Zope.
2
How do I fix CVE-2010-3198?
To fix CVE-2010-3198, upgrade Zope to version 2.10.12 or 2.11.7 or later.
3
What versions of Zope are affected by CVE-2010-3198?
CVE-2010-3198 affects Zope versions 2.10.x prior to 2.10.12 and 2.11.x prior to 2.11.7.
4
What are the consequences of exploiting CVE-2010-3198?
Exploitation of CVE-2010-3198 may lead to a denial of service condition causing ZServer to crash.
5
Is there a patch available for CVE-2010-3198?
Yes, a patch is available by upgrading to Zope versions 2.10.12 or 2.11.7.