SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Multimedia)  >   Gallery Vendors:   Gallery Project
(Debian Issues Fix) 'Gallery' Web-based Image Gallery Software Input Validation Flaw Lets Remote Users Execute Arbitrary Commands on the System
SecurityTracker Alert ID:  1004920
SecurityTracker URL:  http://securitytracker.com/id/1004920
CVE Reference:   GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Aug 1 2002
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): Debian packages prior to 1.2.5-7; upstream prior to 1.3.1
Description:   An input validation flaw was reported in Gallery. A remote user may be able to execute arbitrary commands with the privileges of the web server.

It was reported that a remote user could pass the GALLERY_BASEDIR variable to possibly execute commands with the user privileges of the web server.

Also, a remote user could issue a specially crafted link to a slideshow to avoid authentication requirements and access the image gallery (if the album name is known). A demonstration exploit URL is provided:

http://server:port/gallery/slideshow.php?set_albumName=2002-06-01

Impact:   A remote user may be able to execute arbitrary commands with the privileges of the web server.
Solution:   Debian has released a fix. Debian GNU/Linux 2.2 alias potato does not contain the gallery package and is not affected (in a default configuration).

A fix is provided for Debian GNU/Linux 3.0 alias woody. Woody was released for alpha, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0.dsc
Size/MD5 checksum: 577 34188f0145b780cabc087dc273710428
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5.orig.tar.gz
Size/MD5 checksum: 132099 1a32e57b36ca06d22475938e1e1b19f9
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0.diff.gz
Size/MD5 checksum: 7125 707ec3020491869fa59f66d28e646360

Architecture independent packages:

http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0_all.deb
Size/MD5 checksum: 132290 8f6f152a45bdd3f632fa1cee5e994132

Vendor URL:  gallery.menalto.com/modules.php?op=modload&name=News&file=index (Links to External Site)
Cause:   Input validation error
Underlying OS:  Linux (Debian)

Message History:   This archive entry is a follow-up to the message listed below.
Aug 1 2002 'Gallery' Web-based Image Gallery Software Input Validation Flaw Lets Remote Users Execute Arbitrary Commands on the System



 Source Message Contents

Subject:  [SECURITY] [DSA-138-1] Remote execution exploit in gallery


-----BEGIN PGP SIGNED MESSAGE-----

- ------------------------------------------------------------------------
Debian Security Advisory DSA-138-1                   security@debian.org
http://www.debian.org/security/                         Wichert Akkerman
August  1, 2002
- ------------------------------------------------------------------------


Package        : gallery
Problem type   : remote exploit
Debian-specific: no

A problem was found in gallery (a web-based photo album toolkit): it
was possible to pass in the GALLERY_BASEDIR variable remotely. This
made it possible to execute commands under the uid of web-server.

This has been fixed in version 1.2.5-7 of the Debian package and upstream
version 1.3.1.


- ------------------------------------------------------------------------

Obtaining updates:

  By hand:
    wget URL
        will fetch the file for you.
    dpkg -i FILENAME.deb
        will install the fetched file.

  With apt:
    deb http://security.debian.org/ stable/updates main
        added to /etc/apt/sources.list will provide security updates

Additional information can be found on the Debian security web-pages
at http://www.debian.org/security/

- ------------------------------------------------------------------------

Debian GNU/Linux 2.2 alias potato
- ---------------------------------

  Potato does not contain the gallery package


Debian GNU/Linux 3.0 alias woody
- --------------------------------

  Woody was released for alpha, arm, hppa, i386, ia64, m68k, mips, mipsel,
  powerpc, s390 and sparc.


  Source archives:

    http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0.dsc
      Size/MD5 checksum:      577 34188f0145b780cabc087dc273710428
    http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5.orig.tar.gz
      Size/MD5 checksum:   132099 1a32e57b36ca06d22475938e1e1b19f9
    http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0.diff.gz
      Size/MD5 checksum:     7125 707ec3020491869fa59f66d28e646360

  Architecture independent packages:

    http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-7.woody.0_all.deb
      Size/MD5 checksum:   132290 8f6f152a45bdd3f632fa1cee5e994132

- -- 
- ----------------------------------------------------------------------------
Debian Security team <team@security.debian.org>
http://www.debian.org/security/
Mailing-List: debian-security-announce@lists.debian.org


-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQB1AwUBPUh3FqjZR/ntlUftAQEuJgL/Z9inFQxyaUZHvMqhyyPCBzORFbN4Edgu
67Ue5TXeNpZ4rDSgHAKnKBjeHnA4sw1qhubJlFLwzJVshJHrDbP1IXtesA77VEhx
6nM0V2aWX4HrZVO/OJS57IjbB1/vmrTc
=n6mV
-----END PGP SIGNATURE-----


-- 
To UNSUBSCRIBE, email to debian-security-announce-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC