[geeks] [DSA-138-1] Remote execution exploit in gallery (fwd)
    Jonathan C. Patschke 
    jp at celestrion.net
       
    Thu Aug  1 19:57:15 CDT 2002
    
    
  
I know a lot of you use this package and thought I should pass this along.
-- 
Jonathan Patschke
  "gnu: we aim to fuck up everything with the potential to not suck"
                                                   --alex j avriette
---------- Forwarded message ----------
Date: Thu, 1 Aug 2002 01:47:39 +0200
From: Wichert Akkerman <wichert at wiggy.net>
Reply-To: security at debian.org
To: debian-security-announce at lists.debian.org
Subject: [SECURITY] [DSA-138-1] Remote execution exploit in gallery
Resent-Date: 31 Jul 2002 23:47:47 -0000
Resent-From: debian-security-announce at lists.debian.org
Resent-cc: recipient list not shown: ;
-----BEGIN PGP SIGNED MESSAGE-----
- ------------------------------------------------------------------------
Debian Security Advisory DSA-138-1                   security at debian.org
http://www.debian.org/security/                         Wichert Akkerman
August  1, 2002
- ------------------------------------------------------------------------
Package        : gallery
Problem type   : remote exploit
Debian-specific: no
A problem was found in gallery (a web-based photo album toolkit): it
was possible to pass in the GALLERY_BASEDIR variable remotely. This
made it possible to execute commands under the uid of web-server.
This has been fixed in version 1.2.5-7 of the Debian package and upstream
version 1.3.1.
- ------------------------------------------------------------------------
Obtaining updates:
  By hand:
    wget URL
        will fetch the file for you.
    dpkg -i FILENAME.deb
        will install the fetched file.
  With apt:
    deb http://security.debian.org/ stable/updates main
        added to /etc/apt/sources.list will provide security updates
Additional information can be found on the Debian security web-pages
at http://www.debian.org/security/
- ------------------------------------------------------------------------
Debian GNU/Linux 2.2 alias potato
- ---------------------------------
  Potato does not contain the gallery package
Debian GNU/Linux 3.0 alias woody
- --------------------------------
  Woody was released for alpha, arm, hppa, i386, ia64, m68k, mips, mipsel,
  powerpc, s390 and sparc.
  Source archives:
    http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0.dsc
      Size/MD5 checksum:      577 34188f0145b780cabc087dc273710428
    http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5.orig.tar.gz
      Size/MD5 checksum:   132099 1a32e57b36ca06d22475938e1e1b19f9
    http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0.diff.gz
      Size/MD5 checksum:     7125 707ec3020491869fa59f66d28e646360
  Architecture independent packages:
    http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0_all.deb
      Size/MD5 checksum:   132290 8f6f152a45bdd3f632fa1cee5e994132
- --
- ----------------------------------------------------------------------------
Debian Security team <team at security.debian.org>
http://www.debian.org/security/
Mailing-List: debian-security-announce at lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
iQB1AwUBPUh3FqjZR/ntlUftAQEuJgL/Z9inFQxyaUZHvMqhyyPCBzORFbN4Edgu
67Ue5TXeNpZ4rDSgHAKnKBjeHnA4sw1qhubJlFLwzJVshJHrDbP1IXtesA77VEhx
6nM0V2aWX4HrZVO/OJS57IjbB1/vmrTc
=n6mV
-----END PGP SIGNATURE-----
    
    
More information about the geeks
mailing list