A problem was discovered in the way Zope calculates roles. This problem enables local users to view files that they shouldn't. Updated Zope packages are now available.
In some situations Zope checked the wrong folder hierarchy that could cause it to grant local roles when it should not. In other words: users with privileges in one folder could gain privileges in another folder.
Debian:
This has been fixed in version 2.1.6-5.3 by including the 2000-12-15 hotfix, and it is recommended that you upgrade your zope package immediately. wget url
will fetch the file for you dpkg -i file.deb
will install the referenced file.
Debian GNU/Linux 2.2 alias potato
Potato was released for alpha, arm, i386, m68k, PowerPC and Sparc.
At this moment packages for m68k are not available yet. When they become available they will be announced on http://security.debian.org/