Gallery 1.4.4-pl3 Security Release

Chris Kelly <ckdake-/[email protected]> Tue, 02 Nov 2004 17:10:19 -0500
Newsgroups gmane.comp.web.gallery.announce
Message-ID <[email protected]>
Jim Paris discovered a few security problems in Gallery which have been 
addressed in this security release. The primary problem is a cross site 
scripting vulnerability which allows code to be inserted into a Gallery 
by using specially formed URLs. This code then appears to be part of the 
Gallery.

No risk is posed to the webserver-itself or any non-Gallery data, but a 
Gallery install could be compromised using appropriate code.

All Gallery users are very strongly urged to upgrade to 1.4.4-pl3 
immediately, which fixes this serious problem and will secure your system.

Gallery 1.4.4-pl3 can be downloaded from the 
http://sourceforge.net/project/showfiles.php?group_id=7130


-------------------------------------------------------
This SF.Net email is sponsored by:
Sybase ASE Linux Express Edition - download now for FREE
LinuxWorld Reader's Choice Award Winner for best database on Linux.
http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click
__[ g a l l e r y - a n n o u n c e ]_________________________

[ list info/archive --> http://gallery.sf.net/lists.php ]
[ gallery info/FAQ/download --> http://gallery.sf.net ]