From owner-doc-jp@jp.freebsd.org  Wed Sep  6 12:07:47 2000
Received: (from daemon@localhost)
	by castle.jp.freebsd.org (8.9.3+3.2W/8.7.3) id MAA63045;
	Wed, 6 Sep 2000 12:07:47 +0900 (JST)
	(envelope-from owner-doc-jp@jp.FreeBSD.org)
Received: from tortoise.jp.freebsd.org (root@tortoise.jp.FreeBSD.ORG [210.157.158.41])
	by castle.jp.freebsd.org (8.9.3+3.2W/8.7.3) with ESMTP id MAA63040
	for <doc-jp@jp.freebsd.org>; Wed, 6 Sep 2000 12:07:47 +0900 (JST)
	(envelope-from kuriyama@FreeBSD.org)
Received: from waterblue.imgsrc.co.jp (waterblue.imgsrc.co.jp [2001:218:422:2:2d0:b7ff:fea0:d487])
	by tortoise.jp.freebsd.org (8.9.3+3.2W/8.7.3) with ESMTP/IPv6 id MAA06638
	for <doc-jp@jp.freebsd.org>; Wed, 6 Sep 2000 12:07:46 +0900 (JST)
	(envelope-from kuriyama@FreeBSD.org)
Received: from waterblue.imgsrc.co.jp (localhost [127.0.0.1])
	by waterblue.imgsrc.co.jp (8.11.0/8.11.0) with ESMTP id e8637gG75140
	for <doc-jp@jp.freebsd.org>; Wed, 6 Sep 2000 12:07:43 +0900 (JST)
Date: Wed, 06 Sep 2000 12:07:42 +0900
Message-ID: <7mog229q0x.wl@waterblue.imgsrc.co.jp>
From: Jun Kuriyama <kuriyama@FreeBSD.org>
To: doc-jp@jp.freebsd.org
In-Reply-To: In your message of "3 Sep 2000 00:25:17 GMT"
	<200009030024.JAA28020@mail.geocities.co.jp>
References: <20000814231228.6132C37BF5D@hub.freebsd.org>
	<200009030024.JAA28020@mail.geocities.co.jp>
User-Agent: Wanderlust/1.1.1 (Purple Rain) SEMI/1.13.7 (Awazu) FLIM/1.13.2 (Kasanui) MULE XEmacs/21.1 (patch 12) (Channel Islands) (i386--freebsd)
MIME-Version: 1.0 (generated by SEMI 1.13.7 - "Awazu")
Content-Type: text/plain; charset=ISO-2022-JP
Reply-To: doc-jp@jp.freebsd.org
Precedence: list
X-Distribute: distribute version 2.1 (Alpha) patchlevel 24e+000315
X-Sequence: doc-jp 7676
Subject: [doc-jp 7676] Re: ANNOUNCE: FreeBSD Ports Security Advisory: FreeBSD-SA-00:38.zope
Errors-To: owner-doc-jp@jp.freebsd.org
Sender: owner-doc-jp@jp.freebsd.org
X-Originator: kuriyama@FreeBSD.org

At 3 Sep 2000 00:25:17 GMT,
Hiroki Sato <hrs@geocities.co.jp> wrote:
> 1)
> 
> > The issue involves an inadequately protected method in one of
> > the base classes in the DocumentTemplate package that could allow
> > the contents of DTMLDocuments or DTMLMethods to be changed
> > remotely or through DTML code without forcing proper user
> > authorization.
> 
>  $B$N(B protected method.
> 
>  $B!VHs8x3+%a%=%C%I!W$H$7$^$7$?$,!"0lHLE*$JLu8l$C$F$"$k$s$G$7$g$&$+(B?

$B!!!VCm2r(B C++ $B%j%U%!%l%s%9%^%K%e%"%k!W$G$O!"(Bprivate/protected/public $B$NLu(B
$B8l$,(B $BHs8x3+(B/$B8BDj8x3+(B/$B8x3+(B $B$K$J$C$F$^$9$M$'!#(Bzope $B$,$I$&$$$&0UL#$G(B
protected method $B$H$$$&8@MU$r;H$C$F$k$N$+$o$+$i$s$1$I!#(BC++ $B$N7Q>5$HF1$8(B
$B0UL#$J$i!"Hs8x3+$H$O0UL#$,0c$C$F$7$^$&$+$b$7$l$^$;$s!#(B

> 2) proftpd $B$+$i(B cut & paste $B$7$?$H;W$o$l$k=$@5%_%9$,B8:_$7$^$9!#(B
>    
>    # $BLuCm$rF~$l$F$$$^$9$,!"86J8$r>C$9$H0UL#ITL@$+$b!#(B
>    # If you you.. $B$N(B typo $B$b$"$k!#(B

$B!!$^!"86J8$H$7$C$+$jHf3S$7$J$,$iFI$s$G$$$k?M$,:.Mp$7$J$$$?$a$K$b!"LuCm$r(B
$BF~$l$k7A$G$$$$$s$8$c$J$$$+$H;W$$$^$9!#(B


-- 
Jun Kuriyama <kuriyama@FreeBSD.org> // FreeBSD Project
