Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 124614 - www-apps/gallery 2.0.3 XSS security update released upstream
Summary: www-apps/gallery 2.0.3 XSS security update released upstream
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A4 [noglsa]
Keywords:
: 124612 (view as bug list)
Depends on: 125830
Blocks:
  Show dependency tree
 
Reported: 2006-03-02 02:26 UTC by Andreas Vinsander
Modified: 2006-03-17 04:02 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Possible 2.0.3 ebuild? (gallery-2.0.3.ebuild,1.09 KB, application/octet-stream)
2006-03-02 23:40 UTC, donald webster
no flags Details
faster, harder, better, stronger! (gallery-2.0.3.ebuild,1.13 KB, application/octet-stream)
2006-03-02 23:48 UTC, donald webster
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Vinsander 2006-03-02 02:26:05 UTC
Just got a mail from the gallery-announce list:

Gallery 2.0.3 is now available for download. This release adds no new features. It fixes a minor XSS exploit and an exploit in the session code that could allow users to remotely delete session files. These security flaws were discovered during an independent audit by James Bercegay from GulfTech Security Research who reported them to us and worked with us to provide an appropriate solution. There are no known exploits of these flaws in the wild. However we strongly recommend that you upgrade to version 2.0.3 as soon as possible. Please follow our upgrading instructions and download and install the latest release.

Upgrading is quick and easy and will help you ensure the security of your system.  Visit http://gallery.menalto.com/gallery_2.0.3_released for more details.

Patch Files:
http://codex.gallery2.org/index.php/Gallery2:Download#Upgrades

Instructions:
http://codex.gallery2.org/index.php/Gallery2:Upgrading_to_2.0.x

If you have any questions, please ask in the Gallery 2 forums:
http://gallery.menalto.com/forum/62

regards,
The Gallery Team
Comment 1 donald webster 2006-03-02 23:40:15 UTC
Created attachment 81178 [details]
Possible 2.0.3 ebuild?

I commented out the ffmpeg patch, because I didn't wasn't 100% sure if it needed to be applied.
Comment 2 donald webster 2006-03-02 23:48:54 UTC
Created attachment 81179 [details]
faster, harder, better, stronger!

I've uncommented the patch line after looking at the 2.0.3 source and finding the elderly "singlejpeg" line.
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2006-03-03 10:12:46 UTC
Updating status, web-apps please bump
Comment 4 Renat Lumpau (RETIRED) gentoo-dev 2006-03-05 16:53:21 UTC
bumped
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2006-03-06 09:30:26 UTC
Arches please test and mark 2.0.3 stable
Comment 6 Gustavo Zacarias (RETIRED) gentoo-dev 2006-03-06 09:57:42 UTC
sparc done.
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2006-03-06 11:34:33 UTC
hppa done.
Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2006-03-06 13:03:52 UTC
*** Bug 124612 has been marked as a duplicate of this bug. ***
Comment 9 Chris White (RETIRED) gentoo-dev 2006-03-07 20:41:15 UTC
x86.. handled.
Comment 10 Tobias Scherbaum (RETIRED) gentoo-dev 2006-03-09 12:03:51 UTC
ppc stable
Comment 11 Chris White (RETIRED) gentoo-dev 2006-03-10 12:28:25 UTC
amd64 stable.
Comment 12 donald webster 2006-03-11 05:46:17 UTC
2.0.4 just came out, another security release.  Renaming to 2.0.4 should work fine.
Comment 13 Stefan Cornelius (RETIRED) gentoo-dev 2006-03-11 06:37:11 UTC
Thanks for informing us, I created a new bug for 2.0.4 (bug #125830). Also added the new bug as depending as a headsup, because we'll probably handle both bugs in one GLSA.
Comment 14 Thierry Carrez (RETIRED) gentoo-dev 2006-03-12 03:46:36 UTC
Uncalling arch since we'll have to release 2.0.4 as security fix too.
Comment 15 Renat Lumpau (RETIRED) gentoo-dev 2006-03-15 08:37:08 UTC
in CVS
Comment 16 Stefan Cornelius (RETIRED) gentoo-dev 2006-03-17 04:02:24 UTC
closing without glsa, feel free to reopen if you disagree.