Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.
| Software | From | Fixed in |
|---|---|---|
| apache_gallery / apache_gallery | 0.4 | 0.4.x |
| apache_gallery / apache_gallery | 0.5.1 | 0.5.1.x |
| apache_gallery / apache_gallery | 0.6 | 0.6.x |
| apache_gallery / apache_gallery | 0.5 | 0.5.x |
| apache_gallery / apache_gallery | 0.4.1 | 0.4.1.x |