Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Debian: DSA-138-1 Critical Remote Command Execution in Gallery

debian
Calendar Grey July 31, 2002
Debian Logo
A newly discovered security flaw in the image management platform permits unintended command execution from afar. Fixes and updates have been released for the impacted Ubuntu packages.
A problem was found in gallery (a web-based photo album toolkit): itwas possible to pass in the GALLERY_BASEDIR variable remotely

Summary

Package : gallery
Problem type : remote exploit
Debian-specific: no

A problem was found in gallery (a web-based photo album toolkit): it
was possible to pass in the GALLERY_BASEDIR variable remotely. This
made it possible to execute commands under the uid of web-server.

This has been fixed in version 1.2.5-7 of the Debian package and upstream
version 1.3.1.


------------------------------------------------------------------------

Obtaining updates:

By hand:
wget URL
will fetch the file for you.
dpkg -i FILENAME.deb
will install the fetched file.

With apt:
deb Debian -- Security Information stable/updates main
added to /etc/apt/sources.list will provide security updates

Additional information can be found on the Debian security web-pages
at Debian -- Security Information

------------------------------------------------------------------------

Debian GNU/Linux 2.2 alias potato
---------------------------------

Potato does not contain the gallery package


D...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here