DSA-2334-1 mahara -- several vulnerabilities

Related Vulnerabilities: CVE-2011-2771   CVE-2011-2772   CVE-2011-2773  

Several vulnerabilities were discovered in Mahara, an electronic portfolio, weblog, and resume builder: CVE-2011-2771 Teemu Vesala discovered that missing input sanitising of RSS feeds could lead to cross-site scripting. CVE-2011-2772 Richard Mansfield discovered that insufficient upload restrictions allowed denial of service. CVE-2011-2773 Richard Mansfield discovered that the management of institutions was prone to cross-site request forgery. (no CVE ID available yet) Andrew Nichols discovered a privilege escalation vulnerability in MNet handling. For the oldstable distribution (lenny), this problem has been fixed in version 1.0.4-4+lenny11. For the stable distribution (squeeze), this problem has been fixed in version 1.2.6-2+squeeze3. For the unstable distribution (sid), this problem has been fixed in version 1.4.1-1. We recommend that you upgrade your mahara packages.

Debian Security Advisory

DSA-2334-1 mahara -- several vulnerabilities

Date Reported:
04 Nov 2011
Affected Packages:
mahara
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2011-2771, CVE-2011-2772, CVE-2011-2773.
More information:

Several vulnerabilities were discovered in Mahara, an electronic portfolio, weblog, and resume builder:

  • CVE-2011-2771

    Teemu Vesala discovered that missing input sanitising of RSS feeds could lead to cross-site scripting.

  • CVE-2011-2772

    Richard Mansfield discovered that insufficient upload restrictions allowed denial of service.

  • CVE-2011-2773

    Richard Mansfield discovered that the management of institutions was prone to cross-site request forgery.

  • (no CVE ID available yet)

    Andrew Nichols discovered a privilege escalation vulnerability in MNet handling.

For the oldstable distribution (lenny), this problem has been fixed in version 1.0.4-4+lenny11.

For the stable distribution (squeeze), this problem has been fixed in version 1.2.6-2+squeeze3.

For the unstable distribution (sid), this problem has been fixed in version 1.4.1-1.

We recommend that you upgrade your mahara packages.