Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.announce.security > #3730

[SECURITY] [DSA 5190-1] spip security update

From Moritz Muehlenhoff <jmm@debian.org>
Newsgroups linux.debian.announce.security
Subject [SECURITY] [DSA 5190-1] spip security update
Date 2022-07-26 13:50 +0200
Message-ID <ENrey-dWHm-5@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5190-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
July 26, 2022                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : spip
CVE ID         : not yet available

It was discovered that SPIP, a website engine for publishing, would allow
a malicious user to execute arbitrary code or escalate privileges.
   
For the oldstable distribution (buster), this problem has been fixed
in version 3.2.4-1+deb10u9.

For the stable distribution (bullseye), this problem has been fixed in
version 3.2.11-3+deb11u5.

We recommend that you upgrade your spip packages.

For the detailed security status of spip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/spip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmLf0lkACgkQEMKTtsN8
TjblvA//fRVYAeGTwMkBJXgAakCqYIs2EOy+WwZrjn+fZkK8kh8FZwqKlX7JYaqY
h2NXUHYJNKNQcrFPYghtH8+UtsLMBdNeGJze0XPVO0KwmZk+D/yRyfyxKgPeAMvr
TqhzqO7KA086sJ72XlDxp53SdPnazW6GFMa5hPFqw9LIimMPD4hgGWrzrLeOqGCu
DQjNeYizn2UK8WmTmcrgUD0OwVPnGf+WBwIr8l+SCXGz8i9wIEKw3ImAoLbXyrpQ
Q+zAS5qtx4xymXKFHPNSU2eBK73lHvfQi8f30Ze3TGVZ+aiprpfQJoPLiq5Zqz3Y
GBTWNvf9T8XSAoX6UYc4rQF6sAaCMM0lq6pnsXKjFjU7veb0IUkbF6zJtZ5XeJWW
mlqfADA+OfAkSM6DTAC0zVviiVkosABNDycJEDvt7dPfKlfXj41WqnpEyZZRWINe
cvCcpjsOqdENHn3WzWcMLSV7lpOP9ZlU8kCzf6YdXq+wpLddnJhyFrFyrb9wkj2I
+BTSV+3ECDX7sNlnjAz+CqqUwhNxHgA4IA+HdKVzUCULvIjqYxa6BBGjDft6ocEF
dBtrBxz/20bUoZa1oGtSm4yLR/KB6pvlt58wFz6IIZkbOzrezXK6hZb/SMq5+dmX
bGocTGNo6oOSKysJ6WqE9LmtEpbkvb7yJrfY8jA11Xldgr8B9zY=
=Bw4t
-----END PGP SIGNATURE-----

Back to linux.debian.announce.security | Previous | Next | Find similar | Unroll thread


Thread

[SECURITY] [DSA 5190-1] spip security update Moritz Muehlenhoff <jmm@debian.org> - 2022-07-26 13:50 +0200

csiph-web