OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Wichert Akkerman (wichert_at_wiggy.net)
Date: Wed Jul 31 2002 - 18:47:39 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    -----BEGIN PGP SIGNED MESSAGE-----

    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-138-1 securitydebian.org
    http://www.debian.org/security/ Wichert Akkerman
    August 1, 2002
    - ------------------------------------------------------------------------

    Package : gallery
    Problem type : remote exploit
    Debian-specific: no

    A problem was found in gallery (a web-based photo album toolkit): it
    was possible to pass in the GALLERY_BASEDIR variable remotely. This
    made it possible to execute commands under the uid of web-server.

    This has been fixed in version 1.2.5-7 of the Debian package and upstream
    version 1.3.1.

    - ------------------------------------------------------------------------

    Obtaining updates:

      By hand:
        wget URL
            will fetch the file for you.
        dpkg -i FILENAME.deb
            will install the fetched file.

      With apt:
        deb http://security.debian.org/ stable/updates main
            added to /etc/apt/sources.list will provide security updates

    Additional information can be found on the Debian security web-pages
    at http://www.debian.org/security/

    - ------------------------------------------------------------------------

    Debian GNU/Linux 2.2 alias potato
    - ---------------------------------

      Potato does not contain the gallery package

    Debian GNU/Linux 3.0 alias woody
    - --------------------------------

      Woody was released for alpha, arm, hppa, i386, ia64, m68k, mips, mipsel,
      powerpc, s390 and sparc.

      Source archives:

        http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0.dsc
          Size/MD5 checksum: 577 34188f0145b780cabc087dc273710428
        http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5.orig.tar.gz
          Size/MD5 checksum: 132099 1a32e57b36ca06d22475938e1e1b19f9
        http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0.diff.gz
          Size/MD5 checksum: 7125 707ec3020491869fa59f66d28e646360

      Architecture independent packages:

        http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0_all.deb
          Size/MD5 checksum: 132290 8f6f152a45bdd3f632fa1cee5e994132

    - --
    - ----------------------------------------------------------------------------
    Debian Security team <teamsecurity.debian.org>
    http://www.debian.org/security/
    Mailing-List: debian-security-announcelists.debian.org

    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.3ia
    Charset: noconv

    iQB1AwUBPUh3FqjZR/ntlUftAQEuJgL/Z9inFQxyaUZHvMqhyyPCBzORFbN4Edgu
    67Ue5TXeNpZ4rDSgHAKnKBjeHnA4sw1qhubJlFLwzJVshJHrDbP1IXtesA77VEhx
    6nM0V2aWX4HrZVO/OJS57IjbB1/vmrTc
    =n6mV
    -----END PGP SIGNATURE-----

    -- 
    To UNSUBSCRIBE, email to debian-security-announce-requestlists.debian.org
    with a subject of "unsubscribe". Trouble? Contact listmasterlists.debian.org