You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(5) |
Oct
(2) |
Nov
(5) |
Dec
(1) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
|
Feb
|
Mar
|
Apr
(3) |
May
(2) |
Jun
(1) |
Jul
|
Aug
(3) |
Sep
|
Oct
|
Nov
(1) |
Dec
(1) |
| 2003 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
(1) |
Aug
|
Sep
(2) |
Oct
(3) |
Nov
(2) |
Dec
|
| 2004 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
(1) |
Jun
(1) |
Jul
(3) |
Aug
(2) |
Sep
|
Oct
|
Nov
(2) |
Dec
|
| 2005 |
Jan
(1) |
Feb
(2) |
Mar
(1) |
Apr
(2) |
May
|
Jun
|
Jul
(1) |
Aug
(1) |
Sep
(3) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
| 2006 |
Jan
(2) |
Feb
(2) |
Mar
(3) |
Apr
(2) |
May
|
Jun
|
Jul
|
Aug
(2) |
Sep
|
Oct
(2) |
Nov
(1) |
Dec
|
| 2007 |
Jan
(1) |
Feb
|
Mar
(2) |
Apr
(1) |
May
|
Jun
(1) |
Jul
|
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
(1) |
| 2008 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
(1) |
Aug
(1) |
Sep
(3) |
Oct
(2) |
Nov
(1) |
Dec
|
| 2009 |
Jan
|
Feb
(2) |
Mar
(1) |
Apr
|
May
(1) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(1) |
| 2010 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
| 2011 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
(1) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2012 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
|
Jun
(1) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2013 |
Jan
|
Feb
(1) |
Mar
(1) |
Apr
(1) |
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Gallery A. <gal...@li...> - 2013-06-28 18:40:40
|
Gallery 3.0.9 is now available! We are still hard at work on 3.1, but in the meantime a few more minor security issues needed to be resolved. We've fixed them and recommend that you upgrade to 3.0.9 ASAP. Thanks to Malte Batram and Dhaval Chauhan for their responsible disclosure. We will be rewarding them cash bounties as part of our Security Bounty Program. http://galleryproject.org/gallery_3_0_9 http://downloads.sourceforge.net/gallery/gallery-3.0.9.zip |
|
From: Gallery A. <gal...@li...> - 2013-06-02 21:56:48
|
Gallery 3.0.8 is now available! We're hard at work on 3.1, but in the meantime two security researchers identified small security vulnerabilities in the 3.0.7 release. We've patched them and recommend that you upgrade to 3.0.8 ASAP. Thanks to Mala and Dhaval Chauhan for their responsible disclosure. We'll be rewarding them cash bounties as part of our Security Bounty Program. http://galleryproject.org/gallery_3_0_8 http://downloads.sourceforge.net/gallery/gallery-3.0.8.zip |
|
From: Gallery A. <gal...@li...> - 2013-04-22 13:21:33
|
Gallery 3.0.7 is now available! Yes, we were hoping that 3.0.6 would be the last release in the 3.0 line.. but thanks to Dhiraj Ranka and Shad Laws (a new Gallery core developer - woot!) we've uncovered two small security vulnerabilities that we'd like to patch up, because safety first! Please go ahead and update to 3.0.7 and then sit back and enjoy while we work hard behind the scenes to get 3.1 ready for you. http://galleryproject.org/gallery_3_0_7 http://downloads.sourceforge.net/gallery/gallery-3.0.7.zip |
|
From: Gallery A. <gal...@li...> - 2013-03-20 13:31:47
|
Gallery 3.0.6 is now available! This is likely to be the last release in the 3.0 branch of Gallery - next up we're going to 3.1 and making a lot of big improvements. But before we do that, we wanted to iron out a few kinks and update a few last libraries before we stop working on the 3.0.x code base. This upgrade will be fast and painless, go on.. do it! http://galleryproject.org/gallery_3_0_6 http://downloads.sourceforge.net/gallery/gallery-3.0.6.zip |
|
From: Gallery A. <gal...@li...> - 2013-02-22 14:54:13
|
Gallery 3.0.5 is now available for download. It contains several security fixes as well as a handful of new features. The only major security issue involves someone malicious accessing a copy of Gallery 3 that is not yet installed, so if you already have Gallery 3.0.4 installed and configured there are no known major issues. However, as always we strongly recommend that you upgrade to the latest code. Go on, do it. It's fast and painless. We'd like to thank the following individuals for responsibly reporting these security issues: Michael T. Boos, AMol NAik, Johannes Dahse, Sergey Markov, James 'albino' Kettle, and Johannes Dahse. For their efforts, they will each be receiving bounties of between $100 and $1000 for their help in making Gallery more secure. http://galleryproject.org/gallery_3_0_5 http://downloads.sourceforge.net/gallery/gallery-3.0.5.zip |
|
From: Gallery A. <gal...@li...> - 2012-06-12 18:30:31
|
After several extensive internal and external security audits which discovered 22 distinct vulnerabilities, we are releasing Gallery 3.0.4 as a security release. All of the issues require that someone with malicious intent either have an account with edit permissions, or trick a user with edit permissions into clicking on a malicious link. In most cases, this can only lead to a possible XSS vulnerability, but in several instances it allows arbitrary PHP code execution. We thank the following individuals for reporting these issues: Chalk, Mateusz Goik, James 'albino' Kettle, Emanuel Bronshtein, and Sergey Markov. Due to their efforts, they will each be receiving bounties of $1000 for their help in making Gallery more secure. We recommend that all users of Gallery 3 upgrade as soon as possible. For complete details on this release including what changed, please refer to the official news story: http://gallery.menalto.com/gallery_3_0_4 |
|
From: Gallery A. <gal...@li...> - 2012-04-11 15:23:40
|
We're releasing both Gallery 3.0.3 and Gallery 2.3.2 as security releases. Several researchers, working independently, discovered possible encryption-related vulnerabilities. Low-risk XSS vulnerabilities limited to the administration area were also reported. We thank the following individuals for reporting these issues: James 'albino' Kettle, George Argyros & Aggelos Kiayias, and Emanuel Bronshtein. The CVE id for these issues is CVE-2012-1113. We recommend that all users of Gallery 2 and Gallery 3 upgrade as soon as possible. For complete details on this release including what changed, please refer to the official news story: http://gallery.menalto.com/gallery_3_0_3_and_gallery_2_3_2 |
|
From: Gallery A. <gal...@li...> - 2011-05-25 16:18:22
|
Gallery 3.0.2 is available, woot! This is a bug and stability fix release, but it adds a few new usability features. You should upgrade to Gallery 3.0.2 when you can. Upgrading is quick and easy! Click through on to learn what's new and improved, or just download it now! Details: http://gallery.menalto.com/gallery_3.0.2_released Download: http://downloads.sourceforge.net/gallery/gallery-3.0.2.zip |
|
From: Gallery A. <gal...@li...> - 2011-01-23 05:15:51
|
Gallery 3.0.1 is available! This is a bug and stability fix release, but it also includes an *important security fix*. We strongly advise that you upgrade to Gallery 3.0.1 as soon as possible. Upgrading is quick and easy — don't put it off! More details to learn what's improved in Gallery 3.0.1 or just download it now! For complete details on this release including what changed, please refer to the official news story: http://gallery.menalto.com/gallery_3.0.1_released As a convenience, information about the security fix is included below. Security Fix (Vulnerability CVE-2010-4353) ------------------------------------------ Gallery 3.0 (and beta versions) have a security vulnerability where users with upload permissions can bypass file type restrictions and upload files of any type to the remote system. This vulnerability only affects installations where you've granted upload permissions to users you don't fully trust. Those users could then gain remote access to your system. We strongly recommend that you upgrade immediately. However, if you wish to close the hole without upgrading you can replace or patch modules/gallery/models/item.php with a newer version. Method #1: Replace item.php - Download CVE-2010-4353.zip - Unpack the zip file - Replace modules/gallery/models/item.php with the version contained in the zip file Method #2: Patch item.php - Download CVE-2010-4353.patch.txt - Move CVE-2010-4353.patch.txt into your gallery3 directory - Run patch -p0 < CVE-2010-4353.patch.txt - You should see the following output: patching file modules/gallery/models/item.php We would like to thank Kriss Andsten for responsibly disclosing this security issue. Kriss is a valued member of the Gallery 3 community and he will be receiving a $400 cash reward as part of the Gallery Security Bounty program. If you discover a security vulnerability in any Gallery product, please email sec...@ga... with the details and we will fix it as soon as possible and reward your efforts. -Bharat |
|
From: Gallery A. <gal...@li...> - 2010-10-05 13:41:55
|
Gallery 3.0 is here! It's been two years since Bharat sent out the original call to arms email that started the ball rolling. Since then we've had multiple coding sprints, 9 intermediate releases and seen over 6000 changes from 18+ developers. The final product has gone through many design and coding iterations and has had tremendous feedback from you, the community. Get ready to have a great experience! Download it now: http://downloads.sourceforge.net/gallery/gallery-3.0.zip Get all the details: http://gallery.menalto.com/gallery_3.0_released |
|
From: Gallery A. <gal...@li...> - 2010-07-06 17:12:41
|
The second and final release candidate of Gallery 3.0 (code named Santa Fe) is here! Your feedback in our beta and release candidate phases has been priceless. Now we're just going to make sure that there are no last minute showstoppers before we release the final version and our real journey with Gallery 3 starts! Download it now: http://downloads.sourceforge.net/gallery/gallery-3.0-rc-2.zip or read on for more details http://gallery.menalto.com/gallery_3.0_rc2_released |
|
From: Gallery A. <gal...@li...> - 2009-12-18 18:55:16
|
Even though Gallery 2 isn't under active development anymore, we cleaned up a few loose ends to make it play nicely with PHP 5.3. A very small number of minor enhancements have slipped in, and there are a number of translation updates since the initial release of Gallery 2.3 that we've included in this release. If you're using Gallery 2, you should probably upgrade to 2.3.1 so that your site keeps functioning when you system is upgraded to PHP 5.3. Read on for the details: http://gallery.menalto.com/gallery_2.3.1_released |
|
From: Gallery A. <gal...@li...> - 2009-07-31 16:12:21
|
Dear Gallery User: Gallery's 2009 Season of Usability (SoU) user survey is up and running- and we want you to participate! The purpose of Gallery's SoU project is to learn more about Gallery users (and potential users). So, in order to understand our users and their motivations for using Gallery, we are trying to understand how and why people use photo-management tools in general and what's important to them when using these tools. We want to know their motivations, their tasks, and what qualities they find most desirable in using photo management software, with the ultimate goal of understanding why our users choose Gallery, how they use it, and how we can continue to improve to meet their needs. Help us understand how photos play a part in your life, and how and why you use Gallery to share them. The survey should only take a few minutes; you can access it here: http://survey.usability-methods.com/beta/survey/6720c12644b9439abea48f335b058779/ Your opinion will make a big difference in helping to understand photo sharing in general and in improving Gallery specifically. Thanks. We look forward to hearing from you! Julia Haines Season of Usability student at Gallery |
|
From: Gallery A. <gal...@li...> - 2009-06-07 02:55:58
|
Gallery 3 is finally in beta! We've been hard at work over the past 8 months designing and building a worthy successor to the Gallery line and we are happy to say that we've got something that we think will make you very happy. The big news for this release is that from this point on, we will support upgrades to future releases! But don't take our word for it, download it now! http://gallery.menalto.com/gallery_3.0_beta_1_released Download: http://downloads.sourceforge.net/gallery/gallery-3.0-beta-1.zip |
|
From: Gallery A. <gal...@li...> - 2009-05-05 21:31:37
|
We are very happy to announce that we've put alpha 4 up for public consumption. There's a lot left to do.. but we've come a very long way. Please try it out and provide feedback in the forums or on the announcement on our website. Details: http://gallery.menalto.com/gallery_3.0_alpha_4_released Download: http://downloads.sourceforge.net/gallery/gallery-3.0-alpha-4.zip |
|
From: Gallery A. <gal...@li...> - 2009-03-24 21:21:37
|
Four weeks ago we released Gallery 3.0 Alpha 2 and we're happy to say that the response continues to be overwhelmingly positive. The community support and feedback about features that you'd like to see in the product has been outstanding, and you've helped us track down many issues large and small in the code. To encourage your continued support and patience we're releasing Alpha 3 which has significant improvements! Details: http://gallery.menalto.com/gallery_3.0_alpha_3_released Download: http://downloads.sourceforge.net/gallery/gallery-3.0-alpha-3.zip |
|
From: Gallery A. <gal...@li...> - 2009-02-24 07:56:08
|
Three weeks ago we released Gallery 3.0 Alpha 1 and we're happy to say that the response has been overwhelmingly positive. Many of you have given great feedback about the features that you'd like to see in the product and we've been hard at work trying to get the product ready for release. For those of you who used Alpha 1, you can see that there are still plenty of things that we need to improve. To reward you for your patience and give you a taste of what's to come, we're releasing Alpha 2 which has significant improvements! Features that have been added in alpha 2: * A simpler and powerful Flash based upload UI (we're still tinkering with this!) * Reset / forgot password mechanism * Localized UI with built-in editor (server side support is not finished) * RSS feed for comments * RSS feed for new images or movies * EXIF read support * Import photos from the local webserver * Support for uploading and viewing FLV movie files * Ability to view full size photos * Boolean and full text search Check out the announcement on our website for more details and download information: http://gallery.menalto.com/gallery_3.0_alpha_2_released |
|
From: Gallery A. <gal...@li...> - 2009-02-03 18:02:04
|
After just three months of development, the first public release of Gallery 3.0 is here! Gallery 3.0 Alpha 1 is a technology preview release with most features in place and ready to take a test drive with you. It was back in October at the Gallery Sprint when the Gallery crew set out to create a new Gallery application with simplicity in mind. Three months have passed, the new Gallery version is up and running and indeed much easier to use, customize and extend. Check out the announcement on our website for more details and download information: http://gallery.menalto.com/gallery_3.0_alpha_1_released |
|
From: Gallery A. <gal...@li...> - 2008-11-21 21:47:01
|
Gallery 1.5.10 and Gallery 1.6-RC3 are now available for download. These releases fix one security issue and a handful of other small issues. These releases are also the last official releases of Gallery 1 from the Gallery project. We strongly recommend that all users of Gallery 1.5.9, 1.6-RC2, and earlier upgrade to this release to protect your Gallery installation. You can download them from: http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239 Upgrade instructions are available here: http://codex.gallery2.org/index.php/Gallery1:Upgrading For the full details and what this means for Gallery 1, please read the official announcement: http://gallery.menalto.com/last_official_G1_releases |
|
From: Gallery A. <gal...@li...> - 2008-10-19 03:54:26
|
Gallery 2.3 (Skidoo) is now available for download! It's been almost 20 months since the last major release and Gallery 2.3 is packed with new features and enhancements. Major new features include: A much improved slideshow using PicLens to provide a rich, full screen experience; Comment spam filtering with Akismet; and configurable e-mail notifications. Translations and Integrations: Additionally, 8 languages are now 100% translated, 20 more are over 50% translated, and support has been added for integration with even more 3rd party applications! Security: Like each and every Gallery 2 release before this one, after a professional security audit and internal audits, we have made many improvements to protect your Gallery installation and you. No known exploits exist for the current version of Gallery (R2.2.6), however, we highly recommend that you upgrade to Gallery 2.3 to insure the security of your Gallery installation. Get all the details at: http://gallery.menalto.com/gallery_2.3_released And find the downloads here: http://codex.gallery2.org/Gallery2:Download Thanks for your continued support! -The Gallery Team |
|
From: Gallery A. <gal...@li...> - 2008-10-02 13:22:15
|
Gallery 2.3 RC2 is now available for download! This is second and last release candidate before Gallery 2.3 will be complete. A release candidate helps users like you test out new features and provide feedback so that the final version has as many possible issues resolved. This release candidate includes the same security fixes as Gallery 2.2.6, so anyone using RC1 is strongly encouraged to upgrade to RC2. Download: http://codex.gallery2.org/index.php?title=Gallery2:Download&oldid=18633 Details: http://gallery.menalto.com/gallery_2.3_RC2_released |
|
From: Gallery A. <gal...@li...> - 2008-09-18 13:20:50
|
Gallery 2.2.6 is now available for download. This release fixes critical security issues, no new features have been added. Users of all previous Gallery 2 versions are strongly encouraged to upgrade to version 2.2.6 as soon as possible! The Gallery team thanks Alex Ustinov and Hanno Boeck for reporting the security issues through the right channels and will reward them with a well deserved security bounty Since 2.2.6 is a security release, it shares the same installation requirements as 2.2.5. If you haven't upgraded to 2.2.x yet, please review the Gallery 2.2 release notes for highlights of changes and the requirements. Details: http://gallery.menalto.com/gallery_2.2.6_released Download: http://codex.gallery2.org/Gallery2:Download#Packages |
|
From: Gallery A. <gal...@li...> - 2008-09-16 17:50:01
|
Usability is an area that we always seem to be a few steps behind in, but now is your chance to help us out to fix that. Two groups of students at the University of Michigan's School of Information are spending the semester working on ways to improve Gallery's usability, and they NEED your help! They are seeking some volunteers who are currently using Gallery and are willing to spend 30-45 minutes on the phone (or in person if you live in Ann Arbor, Michigan). As a small token of appreciation for your time, you'll get that warm fuzzy feeling for helping out an open source project and a $10 or more Amazon Gift Card. This is your chance to voice your opinion and help thousands of Gallery users around the world create more enjoyable photo albums. Please email us the team at gal...@ct... with your phone number and available time slots for an interview. They will be conducting interviews between September 12 and September 24 2008. In addition, if you happen to be in Ann Arbor, Michigan, please let them know so they can conduct a face-to-face interview. If you have friends who use Gallery and have comments on their experiences, please refer this message to them. The team would love to talk to them as well. If you have any questions or concerns, please feel free to email them or visit their project website at http://www.adamatorres.com/gallery-project/. Thanks! -The Gallery Team |
|
From: Gallery A. <gal...@li...> - 2008-09-16 15:18:13
|
Gallery 1.5.9 is now available for download. This release fixes several security issues and also resolves a handful of bugs found in Gallery 1.5.8. We recommend that all users of Gallery 1.5.8 and earlier upgrade to this release to protect your Gallery installation. http://gallery.menalto.com/gallery_1.5.9_released After many months of refinement on the alpha versions, Gallery 1.6 Release Candidate 2 is here. This is the second of at least 2 Release Candidates before Gallery 1.6 will be release and recommended for production sites. A release candidate helps users like you test out new features and provide feedback so that the final version has as many possible issues resolved. Please notice that while this release comes with some great new features (e.g. Group Support, Captcha), it contains incompatible changes with older versions of Gallery 1. http://gallery.menalto.com/gallery_1.6-rc2_released Download both: http://sourceforge.net/project/showfiles.php?group_id=7130&package_id=7239 |
|
From: Gallery A. <gal...@li...> - 2008-08-05 17:26:26
|
Today, both Gallery 1.5.8 and Gallery 1.6-RC1 are available! Both include important security fixes, so please read below. Gallery 1.5.8 is now available for download. This release fixes many security issues including some serious security issues. It also resolves as well as a handful of bugs and reorganizes the internal API some. We strongly recommend that all users of Gallery 1.5.7 and earlier upgrade to this release to protect your Gallery installation. You can download Gallery 1.5.8 from the Gallery 1 download page on SourceForge. Details: http://gallery.menalto.com/gallery_1.5.8_released After many months of refinement on the alpha versions, Gallery 1.6 Release Candidate 1 is here. This is the first of at least 2 Release Candidates before Gallery 1.6 will be release and recommended for production sites. A release candidate helps users like you test out new features and provide feedback so that the final version has as many possible issues resolved. Please notice that while this release comes with some great new features (e.g. Group Support, Captcha), it contains incompatible changes with older versions of Gallery 1. Details: http://gallery.menalto.com/gallery_1.6-rc1_released |