Oval Definition:oval:org.mitre.oval:def:13448
Revision Date:2014-06-23Version:20
Title:DSA-1924-1 mahara -- several vulnerabilities
Description:Two vulnerabilities have been discovered in, an electronic portfolio, weblog, and resume builder. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3298 Ruslan Kabalin discovered a issue with resetting passwords, which could lead to a privilege escalation of an institutional administrator account. CVE-2009-3299 Sven Vetsch discovered a cross-site scripting vulnerability via the resume fields. For the stable distribution, these problems have been fixed in version 1.0.4-4+lenny4. The oldstable distribution does not contain mahara. For the testing distribution and the unstable distribution, this problem will be fixed soon. We recommend that you upgrade your mahara packages.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-3298
CVE-2009-3299
DSA-1924-1
Platform(s):Debian GNU/Linux 5.0
Product(s):mahara
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Installed architecture is all
  • AND Packages section
  • mahara-apache2 DPKG is earlier than 1.0.4-4+lenny4
  • OR mahara DPKG is earlier than 1.0.4-4+lenny4
  • BACK