Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o, full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200711-03 ] Gallery: Multiple vulnerabilities
Date: Thu, 01 Nov 2007 23:45:09
Message-Id: 472A7016.1030304@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200711-03
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Low
11 Title: Gallery: Multiple vulnerabilities
12 Date: November 01, 2007
13 Bugs: #191587
14 ID: 200711-03
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 The WebDAV and Reupload modules of Gallery contain multiple unspecified
22 vulnerabilities.
23
24 Background
25 ==========
26
27 Gallery is a PHP based photo album manager.
28
29 Affected packages
30 =================
31
32 -------------------------------------------------------------------
33 Package / Vulnerable / Unaffected
34 -------------------------------------------------------------------
35 1 www-apps/gallery < 2.2.3 >= 2.2.3
36
37 Description
38 ===========
39
40 Merrick Manalastas and Nicklous Roberts have discovered multiple
41 vulnerabilities in the WebDAV and Reupload modules.
42
43 Impact
44 ======
45
46 A remote attacker could exploit these vulnerabilities to bypass
47 security restrictions and rename, replace and change properties of
48 items, or edit item data using WebDAV.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All Gallery users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=www-apps/gallery-2.2.3"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2007-4650
67 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4650
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 http://security.gentoo.org/glsa/glsa-200711-03.xml
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 http://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2007 Gentoo Foundation, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 http://creativecommons.org/licenses/by-sa/2.5
96 -----BEGIN PGP SIGNATURE-----
97 Version: GnuPG v1.4.7 (GNU/Linux)
98 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
99
100 iD8DBQFHKnAWuhJ+ozIKI5gRAqGnAKCKzgiyzZZXPxkTkWyR3TPjjjXrkQCfT7TS
101 s7zfZErUBINg8TgVkkrC9FY=
102 =nzXL
103 -----END PGP SIGNATURE-----
104 --
105 gentoo-announce@g.o mailing list