PDA

View Full Version : Gallery 1.4.4-pl5 Security Release


admin
01-31-2005, 05:54 PM
GALLERY
http://gallery.menalto.com (http://www.vbulletin.com/)
January 26th, 2005 Several days ago, Rafel Ivgi informed us of a possible cross site scripting (definition (http://en.wikipedia.org/wiki/Cross_site_scripting)) problem in current versions of Gallery. The problem and some similar problems discovered by our team has been addressed in Gallery 2 CVS as well as in this release of 1.4.4-pl5.

As with most other cross site scripting problems, No risk is posed to the webserver itself or any non-Gallery data, but a Gallery install could be compromised using appropriate code.

In addition to the security fix, Gallery 1.4.4-pl5 uses the proper parameters for new versions of ImageMagick and fixes some small issues with PHP 5.

All Gallery users are strongly urged to upgrade to 1.4.4-pl5 immediately, which fixes this problem and will secure your system.

Gallery 1.4.4-pl5 can be downloaded from the Gallery Download Page (http://sourceforge.net/project/showfiles.php?group_id=7130).

tffnguy
02-24-2005, 11:37 PM
I downloaded gallery-1.5-RC1.zip today and while attempting to install it got the following warnings. I was hoping you could help me resolve the problems.

---
Serious Warning!
The PHP option 'register_globals' is enabled on your server. Gallery highly recommends that you disable 'register_globals' unless it is required by software on your site. Gallery does not officially support 'register_globals' being enabled, and will attempt to disable it internally


Warning
Missing optional binary pnmcomp. Without pnmcomp and pamcomp gallery will not be able to watermark images, unless you use ImageMagick and have the composite binary installed.

12 of 13 NetPBM binaries located.


Warning
Missing optional binary composite. Without composite gallery will not be able to watermark images, except you use NetPBM and have the pnmcomp binary installed.

2 of 3 ImageMagick binaries located.

======
Warning
I can't find jhead. If it's installed and not in the path of the webserver user that's OK—you can specify the path by hand on the following page. If it's not installed, you can install it yourself. Jhead is a public domain EXIF parser. Source, linux binaries, and windows binaries can be found at the jhead homepage.

I did get jhead and put it in the gallery dir. I assume this is taken care of.
---

Thanks....

David Smith

Chris
02-25-2005, 09:47 AM
David,

Are you trying to upgrade Gallery or are you trying to do a fresh install? Let me know...

tffnguy
02-25-2005, 11:36 AM
Fresh install. I just want to allow my supporting members to be able to use it.

Chris
02-25-2005, 11:44 AM
Fresh install. I just want to allow my supporting members to be able to use it.
Where is the software located on your VDS? I will go in and take a look and see if I can get it working.

tffnguy
02-25-2005, 12:22 PM
Where is the software located on your VDS? I will go in and take a look and see if I can get it working.

You should have a PM email now. Thanks....

Cheers,
David