Gallery 3.0.5 is now available for download. It contains several security fixes as well as a handful of new features. The only major security issue involves someone malicious accessing a copy of Gallery 3 that is not yet installed, so if you already have Gallery 3.0.4 installed and configured there are no known major issues. However, as always we strongly recommend that you upgrade to the latest code. Go on, do it. It's fast and painless.
We'd like to thank the following individuals for responsibly reporting these security issues: Michael T. Boos, AMol NAik, Johannes Dahse, Sergey Markov, James 'albino' Kettle, and Johannes Dahse. For their efforts, they will each be receiving bounties of between $100 and $1000 for their help in making Gallery more secure. Read our Bounties page for details and how to submit any security issues you find.
- you can now limit search to an album
- localization for Thai
- better movie support, easier to install ffmpeg
- better handling for missing and broken images
- digibug print module is gone (because digibug itself is gone)
- 118 bugs and minor enhancements closed
Upgrading Gallery 3
Upgrading is really easy! Unpack the new version, move the var/ directory of the old version to the new version's folder and then either browse to:
or at a shell prompt:
php index.php upgrade
For more detailed upgrade instructions, please refer to
3 User Guide
If you have any overall feedback, please visit the Gallery 3.0.5 Feedback forum topic and let us know! If you have questions,
please visit the Gallery 3 Wiki, the home for Gallery 3 documentation.