![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.62945 |
Category: | Fedora Local Security Checks |
Title: | Fedora Core 10 FEDORA-2008-11218 (gallery2) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to gallery2 announced via advisory FEDORA-2008-11218. Update Information: New upstream, multiple fixes. ChangeLog: * Thu Dec 4 2008 Jon Ciesla - 2.3-1 - Update to new upstream. - Rebased on tarball now that perl path issue is fixed. - Added buildroot wipe to start of install. - Escaped macros in changelog. References: [ 1 ] Bug #462870 - CVE-2008-3662 gallery2 session hijacking vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=462870 [ 2 ] Bug #462883 - CVE-2008-4129 gallery2 arbitrary file disclosure https://bugzilla.redhat.com/show_bug.cgi?id=462883 [ 3 ] Bug #462885 - CVE-2008-4130 gallery2 XSS attack https://bugzilla.redhat.com/show_bug.cgi?id=462885 Solution: Apply the appropriate updates. This update can be installed with the yum update program. Use su -c 'yum update gallery2' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/. http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-11218 Risk factor : Medium CVSS Score: 5.0 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-3662 BugTraq ID: 31231 http://www.securityfocus.com/bid/31231 Bugtraq: 20080918 menalto gallery: Session hijacking vulnerability, CVE-2008-3662 (Google Search) http://www.securityfocus.com/archive/1/496509/100/0/threaded https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00794.html https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00832.html http://seclists.org/fulldisclosure/2008/Sep/0379.html http://security.gentoo.org/glsa/glsa-200811-02.xml http://int21.de/cve/CVE-2008-3662-gallery.html http://secunia.com/advisories/32662 http://secunia.com/advisories/33144 Common Vulnerability Exposure (CVE) ID: CVE-2008-4129 http://secunia.com/advisories/31912 XForce ISS Database: gallery-ziparchives-information-disclosure(45228) https://exchange.xforce.ibmcloud.com/vulnerabilities/45228 Common Vulnerability Exposure (CVE) ID: CVE-2008-4130 http://secunia.com/advisories/31858 XForce ISS Database: gallery-flashanimations-xss(45227) https://exchange.xforce.ibmcloud.com/vulnerabilities/45227 |
Copyright | Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |