CVE-2012-5499: High severity plone cms vulnerability
A denial of service flaw was found in the way Plone, a user friendly and powerful content management system, performed processing of very large values passed to an internal utility function being exposed on an URL. A remote attacker could provide a specially-crafted URL that, when processed would lead to excessive memory consumption.
References: [1] http://plone.org/products/plone/security/advisories/20121106/15 [2] http://plone.org/products/plone/security/advisories/20121106/
Relevant upstream HotFixes: [3] http://plone.org/products/plone-hotfix/releases/20121106
From the OSS post: [4] http://www.openwall.com/lists/oss-security/2012/11/07/4
the pythonscripts.py formatColumns() change from upstream HotFix is relevant to this issue.
Other sources
pythonscripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large value, related to formatColumns.
— GitHub
pythonscripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large value, related to formatColumns.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5499?
CVE-2012-5499 has been classified as a denial of service vulnerability.
How do I fix CVE-2012-5499?
To mitigate CVE-2012-5499, upgrade Plone to versions 4.3b1 or 4.2.3 or later.
What systems are affected by CVE-2012-5499?
CVE-2012-5499 affects various versions of Plone prior to 4.3b1 and 4.2.3.
Can CVE-2012-5499 be exploited remotely?
Yes, a remote attacker can exploit CVE-2012-5499 by sending specially crafted requests.
What kind of attacks can CVE-2012-5499 lead to?
CVE-2012-5499 can lead to a denial of service condition in affected Plone systems.