Debian Security Advisory

DSA-2229-1 spip -- programming error

Date Reported:
01 May 2011
Affected Packages:
spip
Vulnerable:
Yes
Security database references:
No other external database security references currently available.
More information:

A vulnerability has been found in SPIP, a website engine for publishing, which allows a malicious registered author to disconnect the website from its database, resulting in denial of service.

The oldstable distribution (lenny) doesn't include spip.

For the stable distribution (squeeze), this problem has been fixed in version 2.1.1-3squeeze1.

The unstable distribution (sid) will be fixed soon.

We recommend that you upgrade your spip packages.