Gallery 2.0.2 Security Release

gallery-announce-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org Wed, 30 Nov 2005 00:43:16 -0800
Newsgroups gmane.comp.web.gallery.announce
Message-ID <[email protected]>
Gallery 2.0.2 is now available for download. This release adds no new 
features. It fixes a minor XSS exploit, a potential information leak and 
a file disclosure bug in the zipcart module that could allow remote 
visitors to view sensitive files on your webserver. These security flaws 
were discovered during an internal security audit of the Gallery 2 code, 
and there are no known exploits of them in the wild.  However we 
strongly recommend that you upgrade to version 2.0.2 as soon as 
possible. If you're unable to upgrade right away we recommend that you 
*disable the zipcart module* until time permits you to upgrade.  Please 
follow our upgrading instructions and download and install the latest 
release.

Upgrading is quick and easy and will help you ensure the security of 
your system.  Visit http://gallery.menalto.com/gallery_2.0.2_released 
for more details.

Patch Files:
http://codex.gallery2.org/index.php/Gallery2:Download#Upgrades

Instructions:
http://codex.gallery2.org/index.php/Gallery2:Upgrading_to_2.0.x

If you have any questions, please ask in the Gallery 2 forums:
http://gallery.menalto.com/forum/62

regards,
The Gallery Team




-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click
__[ g a l l e r y - a n n o u n c e ]_________________________

[ list info/archive --> http://gallery.sf.net/lists.php ]
[ gallery info/FAQ/download --> http://gallery.sf.net ]