GLSA Bodhisattva
Joined: 13 Jun 2003 Posts: 4087 Location: Dresden, Germany
|
Posted: Tue Jun 15, 2004 7:23 pm Post subject: [ GLSA 200406-10 ] Gallery: Privilege escalation vulnerabili |
|
|
Gentoo Linux Security Advisory
Title: Gallery: Privilege escalation vulnerability (GLSA 200406-10)
Severity: normal
Exploitable: remote
Date: June 15, 2004
Updated: May 22, 2006
Bug(s): #52798
ID: 200406-10
Synopsis
There is a vulnerability in the Gallery photo album software which may
allow an attacker to gain administrator privileges within Gallery.
Background
Gallery is a web application written in PHP which is used to organize
and publish photo albums. It allows multiple users to build and
maintain their own albums. It also supports the mirroring of images on
other servers.
Affected Packages
Package: www-apps/gallery
Vulnerable: <= 1.4.3_p1
Unaffected: >= 1.4.3_p2
Architectures: All supported architectures
Description
There is a vulnerability in the Gallery photo album software which may
allow an attacker to gain administrator privileges within Gallery. A
Gallery administrator has full access to all albums and photos on the
server, thus attackers may add or delete photos at will.
Impact
Attackers may gain full access to all Gallery albums. There is no risk
to the webserver itself, or the server on which it runs.
Workaround
There is no known workaround at this time. All users are encouraged to
upgrade to the latest available version.
Resolution
All users should upgrade to the latest available version of Gallery.
Code: | # emerge sync
# emerge -pv ">=www-apps/gallery-1.4.3_p2"
# emerge ">=www-apps/gallery-1.4.3_p2" |
References
Gallery Announcement
CVE-2004-0522
Last edited by GLSA on Sat Jun 22, 2013 4:16 am; edited 8 times in total |
|