[Erp5-dev] [Fwd: [Zope-dev] Security announcement]

Leonardo Rochael Almeida leonardo at nexedi.com
Wed Jun 29 10:22:36 CEST 2011


The final security announcement has been made.

For ERP5 users, this boils down to the following:

Users running ERP5 on Zope 2.8 are not affected.

Users running ERP5 on Zope 2.12 should upgrade to the latest versions of
Zope 2.12 and of PluggableAuthService.

Cheers,

Leo

Em Ter, 2011-06-28 às 13:07 +0400, Vera Kurpas escreveu: 
> -------- Пересылаемое сообщение --------
> От: Laurence Rowe <l at lrowe.co.uk>
> Кому: plone-users at lists.sourceforge.net, zope at zope.org,
> plone-developers at lists.sourceforge.net, zope-dev <zope-dev at zope.org>,
> plone-announce at lists.sourceforce.net, zope-announce at zope.org
> Тема: [Zope-dev] Security announcement
> Дата: Wed, 22 Jun 2011 18:06:48 +0100
> 
> On behalf of the Plone and Zope Security Teams I'd like to draw your
> attention to a security announcement that has just been published.
> 
> This is a pre-announcement only, it does not contain any vulnerability
> details. Your sites are a safe today as they were yesterday.  However,
> as the problem that has been found is so serious we are giving you
> advance warning that a patch is upcoming and recommending that you
> plan a maintenance period for your sites to coincide with the full
> announcement on Tuesday next week.
> 
> Full details are available at
> http://plone.org/products/plone/security/advisories/pre-announcement-20110622
> 
> You can feel free to ask more questions on the plone-users mailing
> list or in the #plone IRC channel about details and how to protect
> yourself, but it is important to make a plan for this now.  It is
> important to plan down-time at the time specified in that announcement
> or your site will potentially be at risk - following the release of a
> hotfix for the previous serious security vulnerability we received
> reports of automated attacks on unpatched sites.
> 
> 
> Laurence
> _______________________________________________
> Zope-Dev maillist  -  Zope-Dev at zope.org
> https://mail.zope.org/mailman/listinfo/zope-dev
> **  No cross posts or HTML encoding!  **
> (Related lists - 
>  https://mail.zope.org/mailman/listinfo/zope-announce
>  https://mail.zope.org/mailman/listinfo/zope )
> 
> 
> _______________________________________________
> Erp5-dev mailing list
> Erp5-dev at erp5.org
> https://mail.tiolive.com/mailman/listinfo/erp5-dev





More information about the Erp5-dev mailing list