[Full-Disclosure] GLSA: gallery (200309-06)

From: Daniel Ahlberg (alizat_private)
Date: Tue Sep 02 2003 - 04:11:04 PDT

  • Next message: Daniel Ahlberg: "[Full-Disclosure] GLSA: atari800 (200309-07)"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200309-06
    - - - ---------------------------------------------------------------------
    
              PACKAGE : gallery
              SUMMARY : cross site scripting
                 DATE : 2003-09-02 11:11 UTC
              EXPLOIT : remote
    VERSIONS AFFECTED : <gallery-1.3.4_p1
        FIXED VERSION : >=gallery-1.3.4_p1
                  CVE : CAN-2003-0614
    
    - - - ---------------------------------------------------------------------
    
    quote from cve:
    
    "Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 
    through 1.3.4 allows remote attackers to insert arbitrary web script via 
    the searchstring parameter."
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    app-misc/gallery upgrade to gallery-1.3.4_p1 as follows:
    
    emerge sync
    emerge gallery
    emerge clean
    
    - - - ---------------------------------------------------------------------
    alizat_private - GnuPG key is available at http://dev.gentoo.org/~aliz
    - - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.3 (GNU/Linux)
    
    iD8DBQE/VHrIfT7nyhUpoZMRAmnFAJ0cjJdRdiIDH7My8GULs80rpRTi0ACgpf3M
    79zsdZ+rPjDDFG8HGLdPzdg=
    =WE/w
    -----END PGP SIGNATURE-----
    
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Tue Sep 02 2003 - 04:34:07 PDT