Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 39638
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Rajiv Aaron Manglani <rajiv@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 39638 depends on: Show dependency tree
Bug 39638 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-01-27 23:05 0000
from
<http://gallery.menalto.com/modules.php?op=modload&name=News&file=article&sid=107&sid=107>:

Notice if you use Gallery versions 1.3.1, 1.3.2, 1.3.3, 1.4 and 1.4.1 (current
release):

We have discovered a well-hidden but potentially serious security flaw in these
versions of Gallery which can allow a hacker to remotely exploit your
webserver. All Gallery users are strongly urged to upgrade to 1.4.1-pl1
immediately, which fixes this serious problem and will secure your system.

Thanks to Fred (vrotogel) for quickly alerting us to this issue.

Gallery 1.4.1-pl1 can be downloaded from the Gallery Download Page.

If you use version 1.4.1 and would like to patch your existing installation
rather than downloading the full updated version, click to read on...


see also <http://www.securityfocus.com/archive/1/351449>

new version in portage, marked stable. glsa to be sent.

------- Comment #1 From solar 2004-01-27 23:41:10 0000 -------
This is the 3rd time I think I've seen this program has become exploitable.
shame on the coders!

------- Comment #2 From SpanKY 2004-02-10 22:16:44 0000 -------
this was version bumped into stable 25 Jan 2004 by mholzer

GLSA can be sent out as soon as one is made

------- Comment #3 From Tim Yamin (RETIRED) 2004-02-11 13:25:08 0000 -------
GLSA is out: http://article.gmane.org/gmane.linux.gentoo.announce/287

Thanks!

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug