Vulnerability Description
Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maian | Gallery | 2.3 |
| Menalto | Gallery | 2.2.6 |
Related Weaknesses (CWE)
References
- http://gallery.menalto.com/gallery_3_0_3_and_gallery_2_3_2Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=812045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75201
- http://gallery.menalto.com/gallery_3_0_3_and_gallery_2_3_2Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=812045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75201
FAQ
What is CVE-2012-2405?
CVE-2012-2405 is a vulnerability with a CVSS score of 10.0 (HIGH). Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.
How severe is CVE-2012-2405?
CVE-2012-2405 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-2405?
Check the references section above for vendor advisories and patch information. Affected products include: Maian Gallery, Menalto Gallery.