A busy week for the Zope team: on Monday another security
alert was released revealing a potential problem found by Peter Kelly. This
problem involved incorrect protection of data updating for Image and File
objects: any user with DTML editing privileges could update the File or Image
object data directly.
This has been fixed in version 2.1.6-5.4 by including
the 2000-12-19 hotfix, and we recommend that you upgrade your zope package
immediately.