Gallery Releases Gallery 1.5.2-pl2 Security Release
Posted on Sunday, February 12, 2006 @ 08:40:18 CST Gallery 1.5.2-pl2 is now available for download. This release fixes several things:
- A very major data loss issue with the zip download component. If a zip file is not successfully created, Gallery 1.5.2 and Gallery 1.5.2-pl1 will try and delete many more files than they should.
- A very minor security problem where a user with write access to a server could create a specially formatted file, coerce someone with owner privileges in the Gallery to click on a specially formatted link, which could modify stored album data and possibly lead to local code execution. We thank Tom Saville (seregon at bughunter dot net) and his team from Digital Armaments for reporting this us and giving us time to get a patch out.
- Several other minor bugs.
We strongly recommend all Gallery 1.5.2 users upgrade immediately to 1.5.2-pl2 to avoid losing data on your webserver! Download Gallery 1.5.2-pl2 from the Gallery Download Page.
|
| | |
|