Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 104722 - www-apps/gallery - security issues
Summary: www-apps/gallery - security issues
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://gallery.menalto.com/modules.ph...
Whiteboard: B3? [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-03 08:08 UTC by Renat Lumpau (RETIRED)
Modified: 2005-09-09 00:08 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Renat Lumpau (RETIRED) gentoo-dev 2005-09-03 08:08:44 UTC
Description:

Gallery 1.5-pl1 is now available for download. It fixes several major security
issues and it is strongly recommended that all users of 1.5 upgrade to this
release immediately.

Gallery 1.5.1-RC3 is also now available for download. This release fixes several
small issues discovered in the second Release Candidate including the security
problems found in 1.5, and should be the final release candidate before 1.5.1.
Comment 1 Renat Lumpau (RETIRED) gentoo-dev 2005-09-03 08:11:41 UTC
1.5_p1 and 1.5.1_rc3 are in CVS. Security folks - gallery-1.4.4_p6 is stable on
a bunch of arches, so please do your usual dance.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-09-04 11:34:38 UTC
/me dances:

Arches please test and mark 1.5_p1 stable
Target KEYWORDS="alpha amd64 hppa ppc sparc x86"

Didn't really find what the "serious security issues" were, though.
Comment 3 Jason Wever (RETIRED) gentoo-dev 2005-09-04 15:35:04 UTC
Stable on SPARC.
Comment 4 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2005-09-04 17:39:33 UTC
Stable on alpha
Comment 5 Renat Lumpau (RETIRED) gentoo-dev 2005-09-04 19:34:35 UTC
stable on x86
Comment 6 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-09-05 13:13:08 UTC
Stable on ppc and hppa.
Comment 7 Simon Stelling (RETIRED) gentoo-dev 2005-09-05 14:03:12 UTC
amd64 stable
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-09-05 22:11:19 UTC
Time for GLSA decision. This is what I could gather from the Changelog:  
  
2005-08-24 Jay Rossiter <cryptographite@users.sf.net> 1.5-pl1-cvs-b2  
  
        * Fix: Prevent two file exposure bugs in stats module  
          (thanks to ilia for one of them)  
  
   
2005-08-23  Jay Rossiter <cryptographite@users.sf.net>  1.5-pl1-cvs-b1  
  
       * Fix: Prevent HTML tags inside EXIF info from being displayed without  
         escaping.  
 
Based on that I tend to vote NO. 
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2005-09-06 02:17:32 UTC
Here is what I gathered from Debian Changelog :

   * SECURITY:
     + Fix privilege escalation in Postnuke integration.
       References: CAN-2005-2596
     + Fix XSS issue in EXIF tag handling (Closes: #325285)
     + Fix two file exposure bugs in stats module.

CAN-2005-2596 is http://secunia.com/advisories/16389, fixed since 1.5.1RC2, but
maybe unfixed in 1.5_pl1
The other two are http://secunia.com/advisories/16594

I tend to vote yes.
Comment 10 Tavis Ormandy (RETIRED) gentoo-dev 2005-09-08 23:40:59 UTC
"This can be exploited by PostNuke users with any admin privilege levels to gain 
access to other user's albums."

If that's the only impact (along with the xss and file disclosure), I would vote 
NO.
Comment 11 Stefan Cornelius (RETIRED) gentoo-dev 2005-09-08 23:48:20 UTC
i'd say no, they all seem to be pretty minor
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-09-09 00:08:01 UTC
Closing without GLSA. Feel free to reopen if you disagree.