Name : gallery3 Product : Fedora 17 Version : 3.0.8 Release : 1.fc17 URL : http://gallery.menalto.com Summary : Customizable photo gallery web site Description : Gallery is an open source project with the goal to develop and support leading photo sharing web application solutions.
A security flaw was found in the way uploadify and flowplayer SWF files handling functionality of Gallery version 3, an open source project with the goal to develop and support leading photo sharing web application solutions, processed certain URL fragments passed to these files (certain URL fragments were not stripped properly when these files were called via direct URL request(s)). A remote attacker could use this flaw to conduct replay attacks.
[ 1 ] Bug #970599 - CVE-2013-2138 gallery3: Improper stripping of URL fragments in uploadify and flowplayer SWF files might lead to replay attacks [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=970599 [ 2 ] Bug #970598 - CVE-2013-2138 gallery3: Improper stripping of URL fragments in uploadify and flowplayer SWF files might lead to replay attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=970598 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update gallery3' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.