Alerts This Week
Warning Icon 1 854
Alerts This Week
Warning Icon 1 854

Gentoo: 202109-12 Moderate: Portfolio Cross-Site Scripting Vulnerability

gentoo
Calendar Grey September 2, 2003
Dist Gentoo Esm H88
To mitigate the XSS vulnerability in the Gentoo Gallery app (versions 1.1 to 1.3.4), we will implement security measures for safe data handling and user input sanitization
Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1through 1.3.4 allows remote attackers to insert arbitrary web script viathe searchstring parameter.

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-06
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
quote from cve:
"Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter."
SOLUTION
It is recommended that all Gentoo Linux users who are running app-misc/gallery upgrade to gallery-1.3.4_p1 as follows:
emerge sync emerge gallery emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

PACKAGE : gallery
SUMMARY : cross site scripting
DATE : 2003-09-02 11:11 UTC
EXPLOIT : remote
VERSIONS AFFECTED : =gallery-1.3.4_p1
CVE : CAN-2003-0614

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Your message here