Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 475436 - <www-apps/gallery-3.0.9: Two Unspecified Vulnerabilities (CVE-2013-2138)
Summary: <www-apps/gallery-3.0.9: Two Unspecified Vulnerabilities (CVE-2013-2138)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/53964/
Whiteboard: ~? [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-01 17:01 UTC by Agostino Sarubbo
Modified: 2013-10-16 02:12 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-07-01 17:01:05 UTC
From ${URL} :

Description

Two vulnerabilities with an unknown impact have been reported in Gallery.

The vulnerabilities are caused due to unspecified errors. No further information is currently 
available.

The vulnerabilities are reported in versions prior to 3.0.9.


Solution:
Update to version 3.0.9.

Provided and/or discovered by:
The vendor credits Malte Batram and Dhaval Chauhan.

Original Advisory:
http://galleryproject.org/gallery_3_0_9


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 1 Anthony Basile gentoo-dev 2013-07-01 18:35:27 UTC
the vulnerable versions are off the tree and only 3.0.9 remains.
Comment 2 Chris Reffett (RETIRED) gentoo-dev Security 2013-07-03 01:21:46 UTC
blueness reports that this vulnerability only affects the 3.x branch, which is new in tree and has not been stabilized at all. Changing to ~ and closing.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2013-10-16 02:12:58 UTC
CVE-2013-2138 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2138):
  The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do
  not properly remove query parameters and fragments, which allows remote
  attackers to have an unspecified impact via a replay attack.