Bug#573389: Security Issue?

2010-04-28 Thread Gunter Ohrner
Am Dienstag, 27. April 2010 schrieb Al Nikolov: No, not again! See: You're right, I fell victim to the smarty symlink in the gallery2- directory - shame on me! The file I actually changed belonged to smarty 2.6.20-1.2. The gallery package I had installed was 2.3-1 which came from unstable

Bug#573389: Security Issue?

2010-04-27 Thread Gunter Ohrner
Hi! Apparently the difference between the official file and the Debian file was meant to fix a security hole, or at least the developer who added it thought it would. Surprisingly, this fix is not included in the latest Gallery2 code in the official repository. Maybe this change is a

Bug#573389: Security Issue?

2010-04-27 Thread Al Nikolov
tag 573389 moreinfo unreproducible thanks No, not again! See: http://article.gmane.org/gmane.linux.debian.backports.general/6150/match=gallery2+smarty Try: $ dpkg -L gallery2 | grep Smarty_Compiler.class.php -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a