IMPORTANT Gallery v1.4.1-pl1 Security Patch Release
Beckett Madden-Woods <[email protected]> Sat, 24 Jan 2004 23:09:25 -0800
| Newsgroups | gmane.comp.web.gallery.announce |
|---|---|
| Message-ID | <68D9DF7E-4F05-11D8-960C-000502AD806B__45750.9544482038$1075015055@beckettmw.com> |
Notice if you use Gallery versions 1.3.1, 1.3.2, 1.3.3, 1.4 and 1.4.1
(current release):
We have discovered a well-hidden but potentially serious security flaw
in these versions of Gallery which can allow a hacker to remotely
exploit your webserver. All Gallery users are *strongly* urged to
upgrade to 1.4.1-pl1 immediately, which fixes this serious problem and
will secure your system.
Thanks to Fred (vrotogel) for quickly alerting us to this issue.
We work tirelessly to make Gallery as robust as possible. However,
since this is not the first time we've encountered such security holes,
the development team has resolved to immediately add a pro-active
security hole detection scheme to our testing phase to assure that all
of our future releases are thoroughly vetted against these specific
issues.
Gallery 1.4.1-pl1 can be downloaded from the Gallery Download Page:
http://sf.net/project/showfiles.php?group_id=7130
-The Gallery Team
Gallery :: Your photos on your website
http://gallery.sourceforge.net/
-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn
__[ g a l l e r y - a n n o u n c e ]_________________________
[ list info/archive --> http://gallery.sf.net/lists.php ]
[ gallery info/FAQ/download --> http://gallery.sf.net ]