CVE-2007-4650: Unauthorised editing of item properties

Bug #163492 reported by William Grant
260
Affects Status Importance Assigned to Milestone
gallery2 (Debian)
Fix Released
Unknown
gallery2 (Fedora)
Fix Released
Critical
gallery2 (Gentoo Linux)
Fix Released
Low
gallery2 (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Won't Fix
Undecided
Unassigned
Edgy
Won't Fix
Undecided
Unassigned
Feisty
Won't Fix
Undecided
Unassigned
Gutsy
Won't Fix
Undecided
Unassigned
Hardy
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: gallery2

Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using "linked items" in WebDAV and (b) Reupload modules.

Dapper -> Gutsy are affected; Hardy was fixed by a Debian sync.

CVE References

Revision history for this message
In , David (david-redhat-bugs) wrote :

Description of problem:
gallery 2.2.3 has been released as security update.

Revision history for this message
In , Lubomir (lubomir-redhat-bugs) wrote :

A CVE identifier for the issue has beed requested.

Revision history for this message
In , Lubomir (lubomir-redhat-bugs) wrote :

Mitre assigned CVE-2007-4650 to this issue.

Revision history for this message
In , Fedora (fedora-redhat-bugs) wrote :

gallery2-2.2-0.7.svn20070831.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.

William Grant (wgrant)
Changed in gallery2:
status: New → Fix Released
assignee: nobody → fujitsu
status: New → In Progress
assignee: nobody → fujitsu
status: New → In Progress
assignee: nobody → fujitsu
status: New → In Progress
William Grant (wgrant)
Changed in gallery2:
assignee: nobody → fujitsu
status: New → In Progress
Changed in gallery2:
status: Unknown → Fix Released
Changed in gallery2:
status: Unknown → Fix Released
Kees Cook (kees)
Changed in gallery2:
status: In Progress → Triaged
status: In Progress → Triaged
status: In Progress → Triaged
status: In Progress → Triaged
Revision history for this message
Emanuele Gentili (emgent) wrote :

diff ready.

Changed in gallery2:
status: Unknown → New
Changed in gallery2:
status: New → Fix Released
Revision history for this message
Hew (hew) wrote :

Ubuntu Edgy Eft is no longer supported, so a SRU will not be issued for this release. Marking Edgy as Won't Fix.

Changed in gallery2:
status: Triaged → Won't Fix
Revision history for this message
LumpyCustard (orangelumpycustard) wrote :

Please close for Feisty as Won't Fix? This goes for all the other Feisty bugs.

Revision history for this message
Hew (hew) wrote :

Ubuntu Feisty Fawn is no longer supported, so a SRU will not be issued for this release. Marking Feisty as Won't Fix.

Changed in gallery2:
status: Triaged → Won't Fix
Revision history for this message
Sergio Zanchetta (primes2h) wrote :

The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life -
http://www.ubuntu.com/news/ubuntu-7.10-eol . As a result, we are closing the
Gutsy task.

Changed in gallery2 (Ubuntu Gutsy):
status: Triaged → Won't Fix
William Grant (wgrant)
Changed in gallery2 (Ubuntu Gutsy):
assignee: William Grant (wgrant) → nobody
Changed in gallery2 (Ubuntu Feisty):
assignee: William Grant (wgrant) → nobody
Changed in gallery2 (Ubuntu Dapper):
assignee: William Grant (wgrant) → nobody
Changed in gallery2 (Ubuntu Edgy):
assignee: William Grant (wgrant) → nobody
Changed in gallery2 (Gentoo Linux):
importance: Unknown → Low
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. dapper has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against dapper is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in gallery2 (Ubuntu Dapper):
status: Triaged → Won't Fix
Changed in gallery2 (Fedora):
importance: Unknown → Critical
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.