[SECURITY] [DSA 1822-1] New mahara packages fix cross-site scripting

Debian Security Advisory DSA-1822-1
June 23rd, 2009
Package        : mahara
Vulnerability  : insufficient input sanitization
Problem type   : remote
Debian-specific: no
CVE ID         : no CVE ids yet

It was discovered that mahara, an electronic portfolio, weblog, and resume
builder is prone to several cross-site scripting attacks, which allow an
attacker to inject arbitrary HTML or script code and steal potential sensitive
data from other users.

The oldstable distribution (etch) does not contain mahara.

For the stable distribution (lenny), this problem has been fixed in
version 1.0.4-4+lenny3.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 1.1.5-1.

We recommend that you upgrade your mahara packages.

Debian GNU/Linux 5.0 alias lenny
Debian (stable)
