* SECURITY UPDATE: XSS in unvalidated URI attributes
- Added a filter to sanitise user input urls (LP: #888358)
- debian/patches/CVE-2011-2771.patch: upstream patch
- CVE-2011-2771
* SECURITY UPDATE: DoS attack via invalid or excessively large images
- Added a check to evaluate available memory before processing
(LP: #888358)
- debian/patches/CVE-2011-2772.patch: upstream patch
- CVE-2011-2772
* SECURITY UPDATE: XSRF allowing attackers to trick an admin into adding
them to an institution
- Session check added (LP: #888358)
- debian/patches/CVE-2011-2773.patch: upstream patch
- CVE-2011-2773
* SECURITY UPDATE: Prevent masquerading users from jumping as others
- Added a check to prevent jumping as other users. (LP: #888358)
- debian/patches/mnet_masquerading.patch: upstream patch
-- Melissa Draper <email address hidden> Wed, 02 Nov 2011 21:50:04 +0000
This bug was fixed in the package mahara - 1.2.7-1ubuntu0.2
---------------
mahara (1.2.7-1ubuntu0.2) natty-security; urgency=low
* SECURITY UPDATE: XSS in unvalidated URI attributes patches/ CVE-2011- 2771.patch: upstream patch
- Added a filter to sanitise user input urls (LP: #888358)
- debian/
- CVE-2011-2771
* SECURITY UPDATE: DoS attack via invalid or excessively large images patches/ CVE-2011- 2772.patch: upstream patch
- Added a check to evaluate available memory before processing
(LP: #888358)
- debian/
- CVE-2011-2772
* SECURITY UPDATE: XSRF allowing attackers to trick an admin into adding patches/ CVE-2011- 2773.patch: upstream patch
them to an institution
- Session check added (LP: #888358)
- debian/
- CVE-2011-2773
* SECURITY UPDATE: Prevent masquerading users from jumping as others patches/ mnet_masqueradi ng.patch: upstream patch
- Added a check to prevent jumping as other users. (LP: #888358)
- debian/
-- Melissa Draper <email address hidden> Wed, 02 Nov 2011 21:50:04 +0000