Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.66204
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1924-1)
Summary:The remote host is missing an update for the Debian 'mahara' package(s) announced via the DSA-1924-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'mahara' package(s) announced via the DSA-1924-1 advisory.

Vulnerability Insight:
Two vulnerabilities have been discovered in mahara, an electronic portfolio, weblog, and resume builder. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2009-3298

Ruslan Kabalin discovered a issue with resetting passwords, which could lead to a privilege escalation of an institutional administrator account.

CVE-2009-3299

Sven Vetsch discovered a cross-site scripting vulnerability via the resume fields.

For the stable distribution (lenny), these problems have been fixed in version 1.0.4-4+lenny4.

The oldstable distribution (etch) does not contain mahara.

For the testing distribution (squeeze) and the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your mahara packages.

Affected Software/OS:
'mahara' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-3298
BugTraq ID: 36893
http://www.securityfocus.com/bid/36893
Debian Security Information: DSA-1924 (Google Search)
http://www.debian.org/security/2009/dsa-1924
http://www.osvdb.org/59584
http://secunia.com/advisories/37217
http://secunia.com/advisories/37218
http://www.vupen.com/english/advisories/2009/3101
Common Vulnerability Exposure (CVE) ID: CVE-2009-3299
BugTraq ID: 36892
http://www.securityfocus.com/bid/36892
http://www.osvdb.org/59583
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.