[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2579-1] spip security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2579-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Abhijith PA
March 02, 2021                                https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : spip
Version        : 3.1.4-4~deb9u4+deb9u1

It was discovered that SPIP, a website engine for publishing, would
allow a malicious user to perform cross-site scripting attacks, access
sensitive information, or execute arbitrary code.

For Debian 9 stretch, this problem has been fixed in version
3.1.4-4~deb9u4+deb9u1.

We recommend that you upgrade your spip packages.

For the detailed security status of spip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/spip

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmA+Z+sACgkQhj1N8u2c
KO+uCg//U1+XqYIkAFTFZ3rSlR+LHIT5vKu7jOMg1AcG419ucU9sPkd6mUwDXfZX
ROwVRjUSix49Jxon7MkF0K4rMlIPNO89ipXmWUggZohJ7VVe70DYR100ujTkSuY+
Ki5ZY5VoPG8z/KbU6wg3JHw0clNBpBGR9EOIvyjQxQNC0Ye4X/Fwc0Ne87kU6jWl
fUVAhwwts5cOA85UYHArsa4Zsf2iA0Lw9a1SbuvJieuas0eGa4b+ThPTR8erpPQg
gPuohQWA9U0jDf1/rMmTtXFzCUvDE+6VHI2cZEFzmEg+A9j+HG7/MtbvoyRIeRCS
Vcinhq5yWysRtFRauDxNydwJ8PmjHTua8QG93XO8KWEdFm8i+GFwCVNKMNhsB6C3
vC+9nIAz861wi2/FzYeN5eiaIapaeyciiQIz4DNGYDR4Y0jyjgelnxf84RSboh1m
63HaSQ+wyG0kB0rmdAXKTGZF2EwcEV5DYruWViIODNRYWJ+YJnYzbE5aAxBiKxFG
kFPMkHLTXJvENCFGGOXN75R/TOYwAYvsCu3gRjCSqbP4WFqlC5+nfNaWAvUdnPXz
93uPlRfWj3TIf6c91RStpJMwaAePcmkjIOwB5Rlc87sauBvxkXbegfl/RsMa4phC
Dew91kcniVdRdZAk1hkdzYoFAY8ooBZIuQ81KZf6qEdusCXfJcc=
=KjgQ
-----END PGP SIGNATURE-----


Reply to: