Debian Security Advisory DSA 1148-1 (gallery)

Summary
The remote host is missing an update to gallery announced via advisory DSA 1148-1. Several remote vulnerabilities have been discovered in gallery, a web-based photo album. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-2734 A cross-site scripting vulnerability allows injection of web script code through HTML or EXIF information. CVE-2006-0330 A cross-site scripting vulnerability in the user registration allows injection of web script code. CVE-2006-4030 Missing input sanitising in the stats modules allows information disclosure.
Solution
For the stable distribution (sarge) these problems have been fixed in version 1.5-1sarge2. For the unstable distribution (sid) these problems have been fixed in version 1.5-2. We recommend that you upgrade your gallery package. https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201148-1