CVE Vulnerabilities

CVE-2006-3458

Published: Jul 07, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the raw command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.

Affected Software

NameVendorStart VersionEnd Version
ZopeZope2.7.0 (including)2.7.0 (including)
ZopeZope2.7.1 (including)2.7.1 (including)
ZopeZope2.7.2 (including)2.7.2 (including)
ZopeZope2.7.3 (including)2.7.3 (including)
ZopeZope2.7.4 (including)2.7.4 (including)
ZopeZope2.7.5 (including)2.7.5 (including)
ZopeZope2.7.6 (including)2.7.6 (including)
ZopeZope2.7.7 (including)2.7.7 (including)
ZopeZope2.7.8 (including)2.7.8 (including)
ZopeZope2.8.0 (including)2.8.0 (including)
ZopeZope2.8.1 (including)2.8.1 (including)
ZopeZope2.8.2 (including)2.8.2 (including)
ZopeZope2.8.3 (including)2.8.3 (including)
ZopeZope2.8.4 (including)2.8.4 (including)
ZopeZope2.8.5 (including)2.8.5 (including)
ZopeZope2.8.6 (including)2.8.6 (including)
ZopeZope2.8.7 (including)2.8.7 (including)
ZopeZope2.9.0 (including)2.9.0 (including)
ZopeZope2.9.1 (including)2.9.1 (including)
ZopeZope2.9.2 (including)2.9.2 (including)
ZopeZope2.9.3 (including)2.9.3 (including)
Zope2.10Ubuntudevel*
Zope2.9Ubuntudapper*
Zope2.9Ubuntudevel*
Zope2.9Ubuntuedgy*
Zope2.9Ubuntufeisty*

References