cross-site scripting vulnerability in resume blocktype CVE-2009-3299

Bug #463083 reported by François Marier
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mahara (Ubuntu)
Fix Released
Undecided
François Marier
Jaunty
Fix Released
Undecided
Unassigned
Karmic
Fix Released
Undecided
Unassigned
Lucid
Fix Released
Undecided
François Marier

Bug Description

Binary package hint: mahara

Resume fields displayed from within a view were not being escaped properly. Users could add hostile HTML to their resume, add it to a public view and lure other users to it.

Changed in mahara (Ubuntu):
assignee: nobody → François Marier (fmarier)
Revision history for this message
François Marier (fmarier) wrote :

(see debdiffs in LP #463082)

Changed in mahara (Ubuntu Jaunty):
status: New → In Progress
Changed in mahara (Ubuntu Karmic):
status: New → In Progress
Changed in mahara (Ubuntu Lucid):
status: New → Confirmed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mahara - 1.1.5-1ubuntu1

---------------
mahara (1.1.5-1ubuntu1) lucid; urgency=low

  [ Francois Marier ]
  * SECURITY UPDATE: privilege escalation (LP: #463082)
    - debian/patches/CVE-2009-3298.dpatch: fix from upstream
    - CVE-2009-3298
  * SECURITY UPDATE: cross-site scripting vulnerability (LP: #463083)
    - debian/patches/CVE-2009-3299.dpatch: fix from upstream
    - CVE-2009-3299
  * Add dpatch support

 -- Jamie Strandboge <email address hidden> Wed, 04 Nov 2009 11:29:22 -0600

Changed in mahara (Ubuntu Lucid):
status: Confirmed → Fix Released
Changed in mahara (Ubuntu Jaunty):
status: In Progress → Fix Released
Changed in mahara (Ubuntu Karmic):
status: In Progress → Fix Released
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.