Gallery: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200711-03 / gallery |
| Release Date |
November 01, 2007 |
| Latest Revision |
November 11, 2007: 02 |
| Impact |
low |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| www-apps/gallery |
<
2.2.3 |
>=
2.2.3,
<
2.0 |
All supported architectures
|
Related bugreports:
#191587
Synopsis
The WebDAV and Reupload modules of Gallery contain multiple unspecified
vulnerabilities.
2.
Impact Information
Background
Gallery is a PHP based photo album manager.
Description
Merrick Manalastas and Nicklous Roberts have discovered multiple
vulnerabilities in the WebDAV and Reupload modules.
Impact
A remote attacker could exploit these vulnerabilities to bypass
security restrictions and rename, replace and change properties of
items, or edit item data using WebDAV.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Gallery users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/gallery-2.2.3"
|
4.
References
|