Lucene search

K
gentooGentoo FoundationGLSA-200711-03
HistoryNov 01, 2007 - 12:00 a.m.

Gallery: Multiple vulnerabilities

2007-11-0100:00:00
Gentoo Foundation
security.gentoo.org
10

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS

0.01

Percentile

84.1%

Background

Gallery is a PHP based photo album manager.

Description

Merrick Manalastas and Nicklous Roberts have discovered multiple vulnerabilities in the WebDAV and Reupload modules.

Impact

A remote attacker could exploit these vulnerabilities to bypass security restrictions and rename, replace and change properties of items, or edit item data using WebDAV.

Workaround

There is no known workaround at this time.

Resolution

All Gallery users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=www-apps/gallery-2.2.3"
OSVersionArchitecturePackageVersionFilename
Gentooanyallwww-apps/gallery< 2.2.3UNKNOWN

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS

0.01

Percentile

84.1%