Fwd: [vendor-sec] Updated hotfix for Plone CVE 2007-5741

Thijs Kinkhorst thijs at debian.org
Mon Nov 19 11:28:11 UTC 2007


Hi,

Is this something we need to update the DSA for? Please let us know.


thanks,
Thijs

----------  Forwarded Message  ----------

Subject: [vendor-sec] Updated hotfix for Plone CVE 2007-5741
Date: Saturday 17 November 2007 13:18
From: Wichert Akkerman <wichert at wiggy.net>
To: vendor-sec at lst.de

FYI:

The original hotfix for CVE 2007-5741 introduced a stability problem for
environments hosting Plone sites behind apache or other proxies and
could break translations of status messages.

This has been corrected in an updated hotfix:
http://plone.org/products/plone-hotfix/releases/20071106-2

Wichert.

--
Wichert Akkerman <wichert at wiggy.net>    It is simple to make things.
http://www.wiggy.net/                   It is hard to make things simple.
_______________________________________________
Vendor Security mailing list
Vendor Security at lst.de
https://www.lst.de/cgi-bin/mailman/listinfo/vendor-sec

-------------------------------------------------------
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 481 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/pkg-zope-developers/attachments/20071119/a9f053bb/attachment.pgp 


More information about the pkg-zope-developers mailing list