Gallery Unspecified Remote HTML Injection Vulnerability
BID:11602
Info
Gallery Unspecified Remote HTML Injection Vulnerability
| Bugtraq ID: | 11602 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1106 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
Gentoo Linux Gallery Gallery 1.4.4 -pl2 Gallery Gallery 1.4.3 -pl2 Gallery Gallery 1.4.3 -pl1 Gallery Gallery 1.4.2 Gallery Gallery 1.4.1 Gallery Gallery 1.4 -pl2 Gallery Gallery 1.4 -pl1 Gallery Gallery 1.4 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha |
| Not Vulnerable: |
Gallery Gallery 1.4.4 -pl2 |
Discussion
Gallery Unspecified Remote HTML Injection Vulnerability
An unspecified HTML injection vulnerability reportedly affects Gallery. This issue is due to a failure of the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Update: It is reported that the fixes released by the vendor to address this issue are ineffective. Gallery 1.4.4-pl2 is still considered vulnerable to cross-site scripting attacks. Gallery 1.4.4-pl2 is being added to affected packages and the fixes are being removed as well.
An unspecified HTML injection vulnerability reportedly affects Gallery. This issue is due to a failure of the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Update: It is reported that the fixes released by the vendor to address this issue are ineffective. Gallery 1.4.4-pl2 is still considered vulnerable to cross-site scripting attacks. Gallery 1.4.4-pl2 is being added to affected packages and the fixes are being removed as well.
Exploit / POC
Gallery Unspecified Remote HTML Injection Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Gallery Unspecified Remote HTML Injection Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Debian has released an advisory (DSA 642-1) and fixes that address this and other issues in gallery. Please see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Gentoo Linux has released advisory GLSA 200411-10:01 to address this issue in Gallery. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/gallery-1.4.4_p4"
It is reported that the fixes released by the vendor to address this issue are ineffective. Gallery 1.4.4-pl2 is still considered vulnerable to cross-site scripting attacks. The fixes are being removed.
Gallery Gallery 1.4 -pl2
Gallery Gallery 1.4 -pl1
Gallery Gallery 1.4
Gallery Gallery 1.4.1
Gallery Gallery 1.4.2
Gallery Gallery 1.4.3 -pl2
Gallery Gallery 1.4.3 -pl1
Debian Linux 3.0 s/390
Debian Linux 3.0 arm
Debian Linux 3.0 alpha
Debian Linux 3.0 mips
Debian Linux 3.0 mipsel
Debian Linux 3.0 m68k
Debian Linux 3.0 sparc
Debian Linux 3.0 ia-64
Debian Linux 3.0 hppa
Debian Linux 3.0 ppc
Debian Linux 3.0 ia-32
Solution:
The vendor has released an upgrade dealing with this issue.
Debian has released an advisory (DSA 642-1) and fixes that address this and other issues in gallery. Please see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Gentoo Linux has released advisory GLSA 200411-10:01 to address this issue in Gallery. Users of the affected package are urged to execute the following commands with superuser privileges to install the updates:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/gallery-1.4.4_p4"
It is reported that the fixes released by the vendor to address this issue are ineffective. Gallery 1.4.4-pl2 is still considered vulnerable to cross-site scripting attacks. The fixes are being removed.
Gallery Gallery 1.4 -pl2
-
Gallery Gallery Version 1.4.4-pl2
http://sourceforge.net/project/showfiles.php?group_id=7130
Gallery Gallery 1.4 -pl1
-
Gallery Gallery Version 1.4.4-pl2
http://sourceforge.net/project/showfiles.php?group_id=7130
Gallery Gallery 1.4
-
Gallery Gallery Version 1.4.4-pl2
http://sourceforge.net/project/showfiles.php?group_id=7130
Gallery Gallery 1.4.1
-
Gallery Gallery Version 1.4.4-pl2
http://sourceforge.net/project/showfiles.php?group_id=7130
Gallery Gallery 1.4.2
-
Gallery Gallery Version 1.4.4-pl2
http://sourceforge.net/project/showfiles.php?group_id=7130
Gallery Gallery 1.4.3 -pl2
-
Gallery Gallery Version 1.4.4-pl2
http://sourceforge.net/project/showfiles.php?group_id=7130
Gallery Gallery 1.4.3 -pl1
-
Gallery Gallery Version 1.4.4-pl2
http://sourceforge.net/project/showfiles.php?group_id=7130
Debian Linux 3.0 s/390
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 arm
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 alpha
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 mips
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 mipsel
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 m68k
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 sparc
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 ia-64
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 hppa
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 ppc
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
Debian Linux 3.0 ia-32
-
Debian gallery_1.2.5-8woody3_all.deb
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.2.5-8 woody3_all.deb
References
Gallery Unspecified Remote HTML Injection Vulnerability
References:
References:
- Gallery Product Page (Gallery)
- Gallery Version 1.4.4-pl2 Change Log (Gallery)
- Gallery is still vulnerable to Cross-site Scripting attacks (Jon Keating
)