Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 125830 - www-apps/gallery: file inclusion in < 2.0.4
Summary: www-apps/gallery: file inclusion in < 2.0.4
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://gallery.menalto.com/2.0.4_and_...
Whiteboard: C2? [noglsa] DerCorny
Keywords:
: 125826 (view as bug list)
Depends on:
Blocks: 124614
  Show dependency tree
 
Reported: 2006-03-11 06:32 UTC by Stefan Cornelius (RETIRED)
Modified: 2006-03-17 04:01 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Cornelius (RETIRED) gentoo-dev 2006-03-11 06:32:29 UTC
Thanks once again to James Bercegay from GulfTech Security Research for tipping us off to a security vulnerability in Gallery 2.0.3 and the 2.1 release candidates. Your installation is only vulnerable if you have the register_globals setting enabled. If you're vulnerable, an attacker can use this exploit to execute a "local inclusion" exploit, or run code that's already on your server. This is especially dangerous if you allow upload privileges to users you don't trust, and your g2data directory is in a predictable location. We have released Gallery 2.0.4 and 2.1-RC-2a to fix this vulnerability, but it's also very easily patched by hand if you don't want to install a complete update. Read on for more details on how to quickly secure your Gallery install.
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2006-03-11 06:34:56 UTC
web-apps, please provide an ebuild.
Comment 2 Carsten Lohrke (RETIRED) gentoo-dev 2006-03-11 06:44:47 UTC
*** Bug 125826 has been marked as a duplicate of this bug. ***
Comment 3 donald webster 2006-03-11 19:59:32 UTC
simply renaming 2.0.3 -> 2.0.4 does the trick, just like 2.0.2 -> 2.0.3 did.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2006-03-12 03:51:45 UTC
register_globals is evil.
I am tempted to close this one as PEBKAC, but since we have 2.0.3 fixes too...
rl03, would you be so kind ?
Comment 5 Renat Lumpau (RETIRED) gentoo-dev 2006-03-15 08:37:17 UTC
in CVS
Comment 6 Stefan Cornelius (RETIRED) gentoo-dev 2006-03-15 08:40:15 UTC
arches, the same procedure as every year: please test+stable, thank you
Comment 7 Mark Loeser (RETIRED) gentoo-dev 2006-03-15 14:18:32 UTC
x86 done
Comment 8 Jeroen Roovers (RETIRED) gentoo-dev 2006-03-15 16:00:57 UTC
Could we have gallery-2.0.4-full.tar.gz on the mirrors too?
Comment 9 Jeroen Roovers (RETIRED) gentoo-dev 2006-03-16 05:32:10 UTC
hppa done.
Comment 10 Gustavo Zacarias (RETIRED) gentoo-dev 2006-03-16 09:31:16 UTC
sparc stable.
Comment 11 Tobias Scherbaum (RETIRED) gentoo-dev 2006-03-16 11:21:51 UTC
ppc stable
Comment 12 Simon Stelling (RETIRED) gentoo-dev 2006-03-16 11:32:43 UTC
amd64 stable
Comment 13 Stefan Cornelius (RETIRED) gentoo-dev 2006-03-17 01:56:25 UTC
ready for glsa vote, together with bug #124614. Didnt make up my mind yet
Comment 14 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-03-17 03:46:24 UTC
I tend to vote no.
Comment 15 donald webster 2006-03-17 03:54:51 UTC
I'm no dev, but I assume the vote means to mention it on GLSA?  I would also say no for a few reasons:
1) afaik, gentoo's php does not have register global enabled by default
2) there are not any known exploits
3) register global users deserve it :)
Comment 16 Stefan Cornelius (RETIRED) gentoo-dev 2006-03-17 04:01:16 UTC
haha, i like point 3 :)

voting no, too. as always, feel free to reopen if you disagree.