Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <200806121234.04677.hanno@hboeck.de>
Date: Thu, 12 Jun 2008 12:34:01 +0200
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com
Cc: coley@...re.org
Subject: CVE id request: menalto gallery

http://gallery.menalto.com/gallery_2.2.5_released

cite:

Gallery 2.2.5 addresses the following security vulnerabilities:

    * XSS through host and path component of request URL - The complete 
request URL is now properly sanitized (applying the same input filtering as 
for all other inputs). This severe vulnerability affects all modules.
    * Information disclosure in album-select module - Fixed exposure of album 
titles through the album-select module when a guest would add a new album to 
a hidden album.
    * Permission escalation through zip archive extraction - No longer 
creating sub-albums when adding items from a zip archive if the active user 
does not have the necessary permission to do so.
    * Information disclosure through embed.php - embed.php is no longer 
susceptible to spoofing the remote address and thus no longer discloses the 
local filesystem path of the Gallery 2 installation folder.
    * View permissions not enforced for password protected items - No longer 
offering the option to protect non-album items directly and only offering the 
feature for albums since full protection only applies to the items within the 
album.

-- 
Hanno Böck		Blog:		http://www.hboeck.de/
GPG: 3DBD3B20		Jabber/Mail:	hanno@...eck.de

Download attachment "signature.asc " of type "application/pgp-signature" (198 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.