Here's a patched 1.0.9-2 package which I have built and tested. It is based on the upstream 1.0 patch that was sent to vendor-sec.
** Attachment added: "mahara-1.0.9-2ubuntu0.1 debdiff" http://launchpadlibrarian.net/23814149/mahara_xss_fixes.deb.diff ** Changed in: mahara (Ubuntu Jaunty) Status: Confirmed => Fix Committed -- CVE-2009-0660 Multiple XSS vulnerabilities in Mahara 1.0.9 https://bugs.launchpad.net/bugs/340863 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs