CVE-2008-4129
Summary
| CVE | CVE-2008-4129 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-18 20:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gallery | Gallery | 2.2.0 | All | All | All |
| Application | Gallery | Gallery | 2.2.1 | All | All | All |
| Application | Gallery | Gallery | 2.2.2 | All | All | All |
| Application | Gallery | Gallery | 2.2.3 | All | All | All |
| Application | Gallery | Gallery | 2.2.4 | All | All | All |
| Application | Gallery | Gallery | All | All | All | All |
| Application | Gallery | Gallery | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gallery 1.5.9 Released | Gallery | af854a3a-2127-422b-91ae-364da2661108 | gallery.menalto.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Gentoo Linux Documentation -- Gallery: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| [SECURITY] Fedora 9 Update: gallery2-2.3-1.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Security Advisory SA32662 - Gentoo update for gallery - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gallery Symlink ZIP Archive Information Disclosure - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gallery 2.2.6 Security Fix Release | Gallery | af854a3a-2127-422b-91ae-364da2661108 | gallery.menalto.com | Patch |
| [SECURITY] Fedora 8 Update: gallery2-2.3-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Gallery Prior to 2.2.6 Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Fedora update for gallery2 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.