First published: Wed Jun 26 2013(Updated: )
A denial of service flaw was found in the way Plone, a user friendly and powerful content management system, used to previously expand certain zip archives. Remote attacker, authenticated Plone user could issue Zip archive expand request with specially-crafted archive that, when processed would lead to uncontrolled resources consumption (denial of service).
Affected Software | Affected Version | How to fix |
---|---|---|
Plone CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-978482 is classified as a denial of service vulnerability affecting Plone.
To fix REDHAT-BUG-978482, ensure that you update to the latest patched version of Plone.
Authenticated users of Plone are specifically affected by REDHAT-BUG-978482.
The impact of REDHAT-BUG-978482 is that it can be exploited to cause a denial of service in the Plone CMS.
Yes, REDHAT-BUG-978482 can be exploited remotely by an authenticated user of the Plone system.