Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Gentoo GLSA 200406-10: Gallery Normal Severity Privilege Escalation

gentoo
Calendar Grey June 15, 2004
Dist Gentoo Esm H88
The GLSA 200406-10 advisory highlights a serious privilege escalation flaw in Gallery software, allowing unauthorized command execution due to user input validation issues. To address this, users must update to the latest Gallery version with security patches, regularly check for updates, and enforce strict access controls to protect their systems. A comprehensive security audit is also recommended for those affected, ensuring all accounts have strong passwords and monitoring tools are in place for suspicious activities.
There is a vulnerability in the Gallery photo album software which may allow an attacker to gain administrator privileges within Gallery.

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200406-10
                                            https://security.gentoo.org/

Severity: Normal Title: Gallery: Privilege escalation vulnerability Date: June 15, 2004 Bugs: #52798 ID: 200406-10

Synopsis ======= There is a vulnerability in the Gallery photo album software which may allow an attacker to gain administrator privileges within Gallery.
Background ========= Gallery is a web application written in PHP which is used to organize and publish photo albums. It allows multiple users to build and maintain their own albums. It also supports the mirroring of images on other servers.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-misc/gall...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here