CVE-2010-3198

medium
Published 2010-09-08 · Modified 2026-05-19
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
4.3
VIR risk
4.3

Description

ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://mail.zope.org/pipermail/zope-announce/2010-September/002247.html

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugs.launchpad.net/zope2/+bug/627988

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.vupen.com/english/advisories/2010/2275

Package impact

EcosystemPackageVulnerableFixed
python PyPIzope>=2.10.0,<2.10.122.10.12
python PyPIzope>=2.11.0,<2.11.72.11.7
python PyPIzope

Application impact

VendorProductVersionsFixed
zopezope2.10.0-b1
zopezope2.10.0-b2
zopezope2.10.0-c1
zopezope2.10.0-final
zopezope2.10.2
zopezope2.10.2-b1
zopezope2.10.2-final
zopezope2.10.3
zopezope2.10.3-final
zopezope2.10.4-final
zopezope2.10.5
zopezope2.10.6
zopezope2.10.7
zopezope2.10.8
zopezope2.10.9
zopezope2.10.10
zopezope2.10.11
zopezope2.11.0
zopezope2.11.0a1
zopezope2.11.0b1
zopezope2.11.0c1
zopezope2.11.1
zopezope2.11.2
zopezope2.11.3
zopezope2.11.4
zopezope2.11.5
zopezope2.11.6

References

Verify integrity in audit chain (admin only). AS-IS.