drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ungewollte Kommandoausführung in gallery
Name: |
Ungewollte Kommandoausführung in gallery
|
|
ID: |
DSA-138-1 |
|
Distribution: |
Debian |
|
Plattformen: |
Debian potato |
|
Datum: |
Do, 1. August 2002, 13:00 |
|
Referenzen: |
Keine Angabe |
|
Applikationen: |
Gallery |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE-----
------------------------------------------------------------------------ Debian Security Advisory DSA-138-1 security@debian.org http://www.debian.org/security/ Wichert Akkerman August 1, 2002 ------------------------------------------------------------------------
Package : gallery Problem type : remote exploit Debian-specific: no
A problem was found in gallery (a web-based photo album toolkit): it was possible to pass in the GALLERY_BASEDIR variable remotely. This made it possible to execute commands under the uid of web-server.
This has been fixed in version 1.2.5-7 of the Debian package and upstream version 1.3.1.
------------------------------------------------------------------------
Obtaining updates:
By hand: wget URL will fetch the file for you. dpkg -i FILENAME.deb will install the fetched file.
With apt: deb http://security.debian.org/ stable/updates main added to /etc/apt/sources.list will provide security updates
Additional information can be found on the Debian security web-pages at http://www.debian.org/security/
------------------------------------------------------------------------
Debian GNU/Linux 2.2 alias potato ---------------------------------
Potato does not contain the gallery package
Debian GNU/Linux 3.0 alias woody --------------------------------
Woody was released for alpha, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc.
Source archives:
gallery_1.2.5-7.woody.0.dsc Size/MD5 checksum: 577 34188f0145b780cabc087dc273710428 gallery_1.2.5.orig.tar.gz Size/MD5 checksum: 132099 1a32e57b36ca06d22475938e1e1b19f9 gallery_1.2.5-7.woody.0.diff.gz Size/MD5 checksum: 7125 707ec3020491869fa59f66d28e646360
Architecture independent packages:
gallery_1.2.5-7.woody.0_all.deb Size/MD5 checksum: 132290 8f6f152a45bdd3f632fa1cee5e994132
-- ---------------------------------------------------------------------------- Debian Security team <team@security.debian.org> http://www.debian.org/security/ Mailing-List: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv
iQB1AwUBPUh3FqjZR/ntlUftAQEuJgL/Z9inFQxyaUZHvMqhyyPCBzORFbN4Edgu 67Ue5TXeNpZ4rDSgHAKnKBjeHnA4sw1qhubJlFLwzJVshJHrDbP1IXtesA77VEhx 6nM0V2aWX4HrZVO/OJS57IjbB1/vmrTc =n6mV -----END PGP SIGNATURE-----
-- To UNSUBSCRIBE, email to debian-security-announce-request@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
|
|
|
|