<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>191587</bug_id>
          
          <creation_ts>2007-09-07 12:44 0000</creation_ts>
          <short_desc>www-apps/gallery &lt; 2.2.3 WebDAV and Reupload Module Data Manipulation Vulnerabilities (CVE-2007-4650)</short_desc>
          <delta_ts>2007-11-11 14:48:36 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://secunia.com/advisories/26716/</bug_file_loc>
          <status_whiteboard>B4 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>mjf@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          

      

      
          <long_desc isprivate="0">
            <who>mjf@gentoo.org</who>
            <bug_when>2007-09-07 12:44:05 0000</bug_when>
            <thetext>Some vulnerabilities have been reported in Gallery, which can be exploited by malicious users to manipulate data.

The vulnerabilities are caused due to unspecified errors within the WebDAV and Reupload modules, which can be exploited to e.g. rename items, change item properties, replace items, or edit item data via WebDAV.

The vulnerabilities are reported in versions prior to 2.2.3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mjf@gentoo.org</who>
            <bug_when>2007-09-07 12:45:44 0000</bug_when>
            <thetext>CC&apos;ing herd and setting whiteboard status.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wrobel@gentoo.org</who>
            <bug_when>2007-09-07 14:43:01 0000</bug_when>
            <thetext>Gallery-2.2.3 is in the tree.

Since 2.1.2 is apparently vulnerable these are the target archs for stabilization:

alpha amd64 hppa ppc ppc64 sparc x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-09-07 15:35:45 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-09-07 17:47:39 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2007-09-07 18:21:39 0000</bug_when>
            <thetext>amd64/x86 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-09-09 15:53:23 0000</bug_when>
            <thetext>alpha stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-09-09 16:22:00 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>yoswink@gentoo.org</who>
            <bug_when>2007-09-12 08:42:43 0000</bug_when>
            <thetext>Installs and works fine in sparc.

@Security: we are the last, ready to vote.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wrobel@gentoo.org</who>
            <bug_when>2007-09-12 08:51:03 0000</bug_when>
            <thetext>Removed the insecure versions from the tree. web-apps is done here.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-09-12 09:44:07 0000</bug_when>
            <thetext>I tend to vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-09-12 09:45:06 0000</bug_when>
            <thetext>I vote yes.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-09-25 09:43:10 0000</bug_when>
            <thetext>glsa request filed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-11-01 23:51:10 0000</bug_when>
            <thetext>GLSA 200711-03</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gringo@slonko.net</who>
            <bug_when>2007-11-02 10:54:32 0000</bug_when>
            <thetext>None of the security announcements implicitly mentions gallery-1.x as affected or not. From the announcement we could assume that gallery 1.x is affected as all versions before gallery-2.2.3 are affected, but:
- According to page http://codex.gallery2.org/G1-G2_Comparison gallery-1.x does not support WebDAV and does not support module system (patch required)
- Secunia website (URL provided in this bug) mentions only &apos;Gallery 2.x&apos; as affected software
This would indicate that gallery-1.x is not affected by this problem, however:

mac ~ # glsa-check -lnc affected
[A] means this GLSA was already applied,
[U] means the system is not affected and
[N] indicates that the system might be affected.

200711-03 [N] Gallery: Multiple vulnerabilities ( www-apps/gallery ) CVE-2007-4650

I do have gallery-1.5.7 installed on the system (some people still prefer gallery-1.x as it doesn&apos;t require DB backend)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-11-11 14:48:36 0000</bug_when>
            <thetext>glsa-200711-03.xml finally fixed, thanks for the info.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>