security hole in 2.0.2/2.0.3
Bug #35528 reported by
Luis Villa
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
gallery2 (Ubuntu) |
Fix Released
|
High
|
StefanPotyra | ||
Breezy |
Invalid
|
Undecided
|
Unassigned | ||
Dapper |
Fix Released
|
Undecided
|
StefanPotyra |
Bug Description
Gallery 2.0.2 has a security hole:
http://
which is unpatched in the universe version of gallery. It has, apparently, been patched in debian unstable:
http://
Ubuntu should suck down the new upstream package, or specifically the security fix.
CVE References
Changed in gallery2: | |
status: | Unconfirmed → Confirmed |
Changed in gallery2: | |
assignee: | nobody → sistpoty |
To post a comment you must log in.
Since this is a security bug, marking major; I *think* this is the right thing, but since the definitions of severity/priority are unlinked, I can't know for sure.