CVE-2008-4129: Path Traversal
Published Sep 18, 2008
·Updated
Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload (aka zip upload) functionality.
Affected Software
7 affected components
Gallery Gallery=2.2.0
Gallery Gallery=2.2.3
Gallery Gallery=2.2.2
Gallery Gallery=2.2.4
Gallery Gallery<=2.2.5
Gallery Gallery=2.2.1
Gallery Gallery<=1.5.8
Remediation
Patch Available
Patch Available
Patch Available
Event History
Sep 18, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4129?
CVE-2008-4129 has a medium severity rating due to its potential for directory traversal attacks.
2
How do I fix CVE-2008-4129?
To fix CVE-2008-4129, upgrade to Gallery version 1.5.9 or 2.2.6 or later.
3
What types of attacks can CVE-2008-4129 enable?
CVE-2008-4129 can enable remote authenticated users to read arbitrary files on the server.
4
Which versions of Gallery are affected by CVE-2008-4129?
Gallery versions before 1.5.9 and versions 2.x before 2.2.6 are affected by CVE-2008-4129.
5
Is CVE-2008-4129 exploitable by unauthenticated users?
CVE-2008-4129 is not directly exploitable by unauthenticated users; it requires authentication.