Gallery 2.0.3 Security Release

gallery-announce-admin-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org Thu, 02 Mar 2006 00:46:59 -0800
Newsgroups gmane.comp.web.gallery.announce
Message-ID <[email protected]>
Gallery 2.0.3 is now available for download. This release adds no new 
features. It fixes a minor XSS exploit and an exploit in the session 
code that could allow users to remotely delete session files. These 
security flaws were discovered during an independent audit by James 
Bercegay from GulfTech Security Research who reported them to us and 
worked with us to provide an appropriate solution. There are no known 
exploits of these flaws in the wild. However we strongly recommend that 
you upgrade to version 2.0.3 as soon as possible. Please follow our 
upgrading instructions and download and install the latest release.

Upgrading is quick and easy and will help you ensure the security of 
your system.  Visit http://gallery.menalto.com/gallery_2.0.3_released 
for more details.

Patch Files:
http://codex.gallery2.org/index.php/Gallery2:Download#Upgrades

Instructions:
http://codex.gallery2.org/index.php/Gallery2:Upgrading_to_2.0.x

If you have any questions, please ask in the Gallery 2 forums:
http://gallery.menalto.com/forum/62

regards,
The Gallery Team



-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642
__[ g a l l e r y - a n n o u n c e ]_________________________

[ list info/archive --> http://gallery.sf.net/lists.php ]
[ gallery info/FAQ/download --> http://gallery.sf.net ]