Gallery 1.4.4-pl5 Security Release

gallery-announce-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org Wed, 26 Jan 2005 07:22:07 -0500
Newsgroups gmane.comp.web.gallery.announce
Message-ID <[email protected]>
Several days ago, Rafel Ivgi informed us of a possible cross site 
scripting (definition: 
http://en.wikipedia.org/wiki/Cross_site_scripting) problem in current 
versions of Gallery. The problem and some similar problems discovered by 
our team has been addressed in Gallery 2 CVS as well as in this release 
of 1.4.4-pl5.

As with most other cross site scripting problems, No risk is posed to 
the webserver itself or any non-Gallery data, but a Gallery install 
could be compromised using appropriate code.

In addition to the security fix, Gallery 1.4.4-pl5 uses the proper 
parameters for new versions of ImageMagick and fixes some small issues 
with PHP 5.

All Gallery users are strongly urged to upgrade to 1.4.4-pl5 
immediately, which fixes this problem and will secure your system.

Gallery 1.4.4-pl5 can be downloaded from the 
http://sourceforge.net/project/showfiles.php?group_id=7130


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
__[ g a l l e r y - a n n o u n c e ]_________________________

[ list info/archive --> http://gallery.sf.net/lists.php ]
[ gallery info/FAQ/download --> http://gallery.sf.net ]