Debian Security Advisory
DSA-2794-1 spip -- several vulnerabilities
- Date Reported:
- 10 Nov 2013
- Affected Packages:
- spip
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 729172.
In Mitre's CVE dictionary: CVE-2013-4555, CVE-2013-4556, CVE-2013-4557. - More information:
-
Several vulnerabilities have been found in SPIP, a website engine for publishing, resulting in cross-site request forgery on logout, cross-site scripting on author page, and PHP injection.
For the oldstable distribution (squeeze), these problems have been fixed in version 2.1.1-3squeeze7.
For the stable distribution (wheezy), these problems have been fixed in version 2.1.17-1+deb7u2.
For the testing distribution (jessie), these problems will be fixed soon.
For the unstable distribution (sid), these problems have been fixed in version 2.1.24-1.
For the experimental distribution, these problems have been fixed in version 3.0.12-1.
We recommend that you upgrade your spip packages.