Home | Docs | Forums | Lists | Bugs | Planet | Store | GMN | Get Gentoo!
Not eligible to see or edit group visibility for this bug.
View Bug Activity | Format For Printing | XML | Clone This Bug
See URL.
v2.2.4 has some critical cross-site scripting bugs. Please bump the ebuild to 2.2.5 http://gallery.menalto.com/gallery_2.2.5_released
Thanks for the note. Bumped to 2.2.5. I'm not 100% certain it makes sense to stabilize this as 2.2.5 is still affected by bug #213322. In case it should be stabilized, the target archs are: alpha amd64 hppa ppc ppc64 sparc x86
I think we should go ahead stabilizing, as #213322 is not a "real" issue (that's why upstream decided to move this on to 2.3), it only may affect thirdparty plugins and opens no vulnerability in gallery core.
x86 stable
ppc64 stable
amd64 stable
alpha/sparc stable
Stable for HPPA.
ppc stable and re-adding hppa, your keyword seems to be missing
(In reply to comment #9) > ppc stable and re-adding hppa, your keyword seems to be missing Thanks. Fixed.
Removed vulnerable gallery-2.2.4. webapps done.
removing ppc from cc ...
CVE-2008-2720: Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of a URL. CVE-2008-2721: Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by attempting to add a new album to a hidden album. CVE-2008-2722: Menalto Gallery before 2.2.5 allows remote attackers to bypass permissions for sub-albums via a ZIP archive. CVE-2008-2723: embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address." CVE-2008-2724: Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attackers to bypass intended access restrictions.
I vote NO.
web-app, so I vote NO.