Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 4 Aug 2001 10:29:00 -0700 (PDT)
From:      Neil Blakey-Milner <nbm@FreeBSD.org>
To:        cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   cvs commit: ports/www/zope Makefile distinfo pkg-plist
Message-ID:  <200108041729.f74HT0057042@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help
nbm         2001/08/04 10:29:00 PDT

  Modified files:
    www/zope             Makefile distinfo pkg-plist 
  Log:
  Acqusition context checking hotfix
  
  ``The issue involves an error in the '_check_context' method of the
  AccessControl.User.BasicUser class. The bug made it possible to access
  Zope objects via acquisition that a user would not otherwise have access
  to. This issue could allow users with enough internal knowledge of Zope
  to perform actions higher in the object hierarchy than they should be
  able to.''
  
  Revision  Changes    Path
  1.30      +8 -6      ports/www/zope/Makefile
  1.18      +1 -0      ports/www/zope/distinfo
  1.22      +4 -0      ports/www/zope/pkg-plist


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200108041729.f74HT0057042>