gallery: multiple vulnerabilities
| Package(s): | gallery | CVE #(s): | CVE-2008-3600 CVE-2008-3662 CVE-2008-4129 CVE-2008-4130 | ||||||||||||||||
| Created: | November 12, 2008 | Updated: | December 15, 2008 | ||||||||||||||||
| Description: | From the Gentoo advisory: * Digital Security Research Group reported a directory traversal vulnerability in contrib/phpBB2/modules.php in Gallery 1, when register_globals is enabled (CVE-2008-3600). * Hanno Boeck reported that Gallery 1 and 2 did not set the secure flag for the session cookie in an HTTPS session (CVE-2008-3662). * Alex Ustinov reported that Gallery 1 and 2 does not properly handle ZIP archives containing symbolic links (CVE-2008-4129). * The vendor reported a Cross-Site Scripting vulnerability in Gallery 2 (CVE-2008-4130). | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
