Date: Sat, 4 Aug 2001 10:29:00 -0700 (PDT) From: Neil Blakey-Milner <nbm@FreeBSD.org> To: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: cvs commit: ports/www/zope Makefile distinfo pkg-plist Message-ID: <200108041729.f74HT0057042@freefall.freebsd.org>
next in thread | raw e-mail | index | archive | help
nbm 2001/08/04 10:29:00 PDT
Modified files:
www/zope Makefile distinfo pkg-plist
Log:
Acqusition context checking hotfix
``The issue involves an error in the '_check_context' method of the
AccessControl.User.BasicUser class. The bug made it possible to access
Zope objects via acquisition that a user would not otherwise have access
to. This issue could allow users with enough internal knowledge of Zope
to perform actions higher in the object hierarchy than they should be
able to.''
Revision Changes Path
1.30 +8 -6 ports/www/zope/Makefile
1.18 +1 -0 ports/www/zope/distinfo
1.22 +4 -0 ports/www/zope/pkg-plist
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200108041729.f74HT0057042>
