Gallery PostNuke Integration Access Validation Vulnerability
BID:14547
Info
Gallery PostNuke Integration Access Validation Vulnerability
| Bugtraq ID: | 14547 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-2596 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2005 12:00AM |
| Updated: | Aug 11 2005 12:00AM |
| Credit: | Discovery credited to ONda. |
| Vulnerable: |
Gallery Gallery 1.5 Gallery Gallery 1.4.4 -pl5 Gallery Gallery 1.4.4 -pl4 Gallery Gallery 1.4.4 -pl3 Gallery Gallery 1.4.4 -pl2 Gallery Gallery 1.4.3 -pl2 Gallery Gallery 1.4.3 -pl1 Gallery Gallery 1.4.2 Gallery Gallery 1.4.1 Gallery Gallery 1.4 -pl2 Gallery Gallery 1.4 -pl1 Gallery Gallery 1.4 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
Gallery PostNuke Integration Access Validation Vulnerability
Gallery is prone to an access validation issue when integrated with PostNuke. This issue could allow any user with any level of admin privileges in PostNuke to also have admin privileges over the entire Gallery.
This issue has been addressed in Gallery 1.5.1-RC2.
Gallery is prone to an access validation issue when integrated with PostNuke. This issue could allow any user with any level of admin privileges in PostNuke to also have admin privileges over the entire Gallery.
This issue has been addressed in Gallery 1.5.1-RC2.
Exploit / POC
Gallery PostNuke Integration Access Validation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Gallery PostNuke Integration Access Validation Vulnerability
Solution:
Debian Linux has released security advisory DSA 879-1 with fixes addressing this issue. Please see the referenced advisory for further details on obtaining and applying the appropriate updates.
The vendor has addressed this issue in Gallery 1.5.1-RC2:
Gallery Gallery 1.4
Gallery Gallery 1.4 -pl2
Gallery Gallery 1.4 -pl1
Gallery Gallery 1.4.1
Gallery Gallery 1.4.2
Gallery Gallery 1.4.3 -pl1
Gallery Gallery 1.4.3 -pl2
Gallery Gallery 1.4.4 -pl3
Gallery Gallery 1.4.4 -pl2
Gallery Gallery 1.4.4 -pl5
Gallery Gallery 1.4.4 -pl4
Gallery Gallery 1.5
Solution:
Debian Linux has released security advisory DSA 879-1 with fixes addressing this issue. Please see the referenced advisory for further details on obtaining and applying the appropriate updates.
The vendor has addressed this issue in Gallery 1.5.1-RC2:
Gallery Gallery 1.4
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4 -pl2
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4 -pl1
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4.1
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4.2
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4.3 -pl1
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4.3 -pl2
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4.4 -pl3
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4.4 -pl2
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4.4 -pl5
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.4.4 -pl4
-
Gallery gallery-1.5.1-RC2
http://sourceforge.net/project/showfiles.php?group_id=7130&package_id= 7239&release_id=348064
Gallery Gallery 1.5
-
Debian gallery_1.5-1sarge1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/g/gallery/gallery_1.5-1sa rge1_all.deb
References
Gallery PostNuke Integration Access Validation Vulnerability
References:
References:
- All postnuke users are superusers! (Gallery)
- Gallery 1.5.1-RC2 Release Notes (Gallery)
- Gallery Product Page (Gallery)