Gallery 1.3.4-p1 security release

"Bharat Mediratta" <[email protected]> Sun, 27 Jul 2003 16:25:25 -0700
Newsgroups gmane.comp.web.gallery.announce
Message-ID <011801c35496$60928af0$0b05000a@firebrand>
We received email this morning from Larry Nguyen, an alert and 
responsible Gallery user who notified us about a cross-site-scripting 
flaw in Gallery. This security flaw can allow a malicious user to craft 
a URL that executes Javascript code on your website.

We estimate the security risk of this flaw to be relatively minor, however 
we take all security issues very seriously. You can download patch 
instructions or a complete version of Gallery including the new changes 
from the Gallery download page:

    http://sourceforge.net/project/showfiles.php?group_id=7130

For more information on the vulnerability, cross site scripting, and a 
simple one-character-change quick fix please read the news story on the
Gallery website:

    http://gallery.sourceforge.net/article.php?sid=82

regards,
Gallery Dev Team




-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01
__[ g a l l e r y - a n n o u n c e ]_________________________

[ list info/archive --> http://gallery.sf.net/lists.php ]
[ gallery info/FAQ/download --> http://gallery.sf.net ]