Gallery Authentication Bypass Vulnerability
BID:10451
Info
Gallery Authentication Bypass Vulnerability
| Bugtraq ID: | 10451 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2004 12:00AM |
| Updated: | Jun 02 2004 12:00AM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
Gallery Gallery 1.4.3 -pl1 Gallery Gallery 1.4.2 Gallery Gallery 1.4.1 Gallery Gallery 1.4 -pl2 Gallery Gallery 1.4 -pl1 Gallery Gallery 1.4 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: |
Gallery Gallery 1.4.3 -pl2 |
Discussion
Gallery Authentication Bypass Vulnerability
It has been disclosed that an attacker can bypass Gallery's authentication process, and log in as any user without a password.
An attacker can override configuration variables by passing them in GET, POST or cookie arguments. Gallery simulates the 'register_globals' PHP setting by extracting the values of the various $HTTP_ global variables into the global namespace. Therefore, regardless of the 'register_globals' PHP setting, an attacker can override configuration variables.
An attacker can change configuration variables and cause Gallery to skip the authentication steps.
Versions prior to 1.4.3-pl2 are reported to be vulnerable.
It has been disclosed that an attacker can bypass Gallery's authentication process, and log in as any user without a password.
An attacker can override configuration variables by passing them in GET, POST or cookie arguments. Gallery simulates the 'register_globals' PHP setting by extracting the values of the various $HTTP_ global variables into the global namespace. Therefore, regardless of the 'register_globals' PHP setting, an attacker can override configuration variables.
An attacker can change configuration variables and cause Gallery to skip the authentication steps.
Versions prior to 1.4.3-pl2 are reported to be vulnerable.
Exploit / POC
Gallery Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gallery Authentication Bypass Vulnerability
Solution:
The vendor has released an upgraded version that resolves this issue.
Debian has released advisory DSA 512-1 addressing this issue. Please see the referenced advisory for further information and fixes.
Gentoo has released a security advisory (GLSA 200406-10) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=app-misc/gallery-1.4.3_p2"
emerge ">=app-misc/gallery-1.4.3_p2"
Gallery Gallery 1.4 -pl2
Gallery Gallery 1.4 -pl1
Gallery Gallery 1.4
Gallery Gallery 1.4.1
Gallery Gallery 1.4.2
Gallery Gallery 1.4.3 -pl1
Solution:
The vendor has released an upgraded version that resolves this issue.
Debian has released advisory DSA 512-1 addressing this issue. Please see the referenced advisory for further information and fixes.
Gentoo has released a security advisory (GLSA 200406-10) to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge sync
emerge -pv ">=app-misc/gallery-1.4.3_p2"
emerge ">=app-misc/gallery-1.4.3_p2"
Gallery Gallery 1.4 -pl2
-
Gallery gallery-1.4.3-pl2.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.4.3-pl2.tar.gz?do wnload
Gallery Gallery 1.4 -pl1
-
Gallery gallery-1.4.3-pl2.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.4.3-pl2.tar.gz?do wnload
Gallery Gallery 1.4
-
Gallery gallery-1.4.3-pl2.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.4.3-pl2.tar.gz?do wnload
Gallery Gallery 1.4.1
-
Gallery gallery-1.4.3-pl2.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.4.3-pl2.tar.gz?do wnload
Gallery Gallery 1.4.2
-
Gallery gallery-1.4.3-pl2.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.4.3-pl2.tar.gz?do wnload
Gallery Gallery 1.4.3 -pl1
-
Gallery gallery-1.4.3-pl1_to_pl2.patch.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.4.3-pl1_to_pl2.pa tch.gz?download -
Gallery gallery-1.4.3-pl2.tar.gz
http://prdownloads.sourceforge.net/gallery/gallery-1.4.3-pl2.tar.gz?do wnload
References
Gallery Authentication Bypass Vulnerability
References:
References:
- Gallery 1.4.3-pl2 Security Release (Gallery)
- Gallery Product Page (Gallery)