Debian DSA-2206-1 : mahara - several vulnerabilities

medium Nessus Plugin ID 53211

Synopsis

The remote Debian host is missing a security-related update.

Description

Two security vulnerabilities have been discovered in Mahara, a fully featured electronic portfolio, weblog, resume builder and social networking system :

- CVE-2011-0439 A security review commissioned by a Mahara user discovered that Mahara processes unsanitized input which can lead to cross-site scripting (XSS).

- CVE-2011-0440 Mahara Developers discovered that Mahara doesn't check the session key under certain circumstances which can be exploited as cross-site request forgery (CSRF) and can lead to the deletion of blogs.

Solution

Upgrade the mahara package.

For the old stable distribution (lenny) these problems have been fixed in version 1.0.4-4+lenny8.

For the stable distribution (squeeze) these problems have been fixed in version 1.2.6-2+squeeze1.

See Also

https://packages.debian.org/source/squeeze/mahara

https://www.debian.org/security/2011/dsa-2206

Plugin Details

Severity: Medium

ID: 53211

File Name: debian_DSA-2206.nasl

Version: 1.11

Type: local

Agent: unix

Published: 3/30/2011

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:mahara, cpe:/o:debian:debian_linux:5.0, cpe:/o:debian:debian_linux:6.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 3/29/2011

Reference Information

CVE: CVE-2011-0439, CVE-2011-0440

BID: 47033

DSA: 2206