<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>125830</bug_id>
          
          <creation_ts>2006-03-11 06:32 0000</creation_ts>
          <short_desc>www-apps/gallery: file inclusion in &lt; 2.0.4</short_desc>
          <delta_ts>2006-03-17 04:01:16 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://gallery.menalto.com/2.0.4_and_2.1_rc_2a_update</bug_file_loc>
          <status_whiteboard>C2? [noglsa] DerCorny</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>124614</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>dercorny@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>fryfrog@gmail.com</cc>
    
    <cc>jer@gentoo.org</cc>
    
    <cc>moixa@gmx.ch</cc>
    
    <cc>web-apps@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-03-11 06:32:29 0000</bug_when>
            <thetext>Thanks once again to James Bercegay from GulfTech Security Research for tipping us off to a security vulnerability in Gallery 2.0.3 and the 2.1 release candidates. Your installation is only vulnerable if you have the register_globals setting enabled. If you&apos;re vulnerable, an attacker can use this exploit to execute a &quot;local inclusion&quot; exploit, or run code that&apos;s already on your server. This is especially dangerous if you allow upload privileges to users you don&apos;t trust, and your g2data directory is in a predictable location. We have released Gallery 2.0.4 and 2.1-RC-2a to fix this vulnerability, but it&apos;s also very easily patched by hand if you don&apos;t want to install a complete update. Read on for more details on how to quickly secure your Gallery install.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-03-11 06:34:56 0000</bug_when>
            <thetext>web-apps, please provide an ebuild.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-03-11 06:44:47 0000</bug_when>
            <thetext>*** Bug 125826 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fryfrog@gmail.com</who>
            <bug_when>2006-03-11 19:59:32 0000</bug_when>
            <thetext>simply renaming 2.0.3 -&gt; 2.0.4 does the trick, just like 2.0.2 -&gt; 2.0.3 did.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2006-03-12 03:51:45 0000</bug_when>
            <thetext>register_globals is evil.
I am tempted to close this one as PEBKAC, but since we have 2.0.3 fixes too...
rl03, would you be so kind ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rl03@gentoo.org</who>
            <bug_when>2006-03-15 08:37:17 0000</bug_when>
            <thetext>in CVS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-03-15 08:40:15 0000</bug_when>
            <thetext>arches, the same procedure as every year: please test+stable, thank you</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2006-03-15 14:18:32 0000</bug_when>
            <thetext>x86 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2006-03-15 16:00:57 0000</bug_when>
            <thetext>Could we have gallery-2.0.4-full.tar.gz on the mirrors too?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2006-03-16 05:32:10 0000</bug_when>
            <thetext>hppa done.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2006-03-16 09:31:16 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2006-03-16 11:21:51 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2006-03-16 11:32:43 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-03-17 01:56:25 0000</bug_when>
            <thetext>ready for glsa vote, together with bug #124614. Didnt make up my mind yet</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-03-17 03:46:24 0000</bug_when>
            <thetext>I tend to vote no.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fryfrog@gmail.com</who>
            <bug_when>2006-03-17 03:54:51 0000</bug_when>
            <thetext>I&apos;m no dev, but I assume the vote means to mention it on GLSA?  I would also say no for a few reasons:
1) afaik, gentoo&apos;s php does not have register global enabled by default
2) there are not any known exploits
3) register global users deserve it :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-03-17 04:01:16 0000</bug_when>
            <thetext>haha, i like point 3 :)

voting no, too. as always, feel free to reopen if you disagree.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>