-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2579-1 debian-...@lists.debian.org https://www.debian.org/lts/security/ Abhijith PA March 02, 2021 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : spip Version : 3.1.4-4~deb9u4+deb9u1 It was discovered that SPIP, a website engine for publishing, would allow a malicious user to perform cross-site scripting attacks, access sensitive information, or execute arbitrary code. For Debian 9 stretch, this problem has been fixed in version 3.1.4-4~deb9u4+deb9u1. We recommend that you upgrade your spip packages. For the detailed security status of spip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/spip Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmA+Z+sACgkQhj1N8u2c KO+uCg//U1+XqYIkAFTFZ3rSlR+LHIT5vKu7jOMg1AcG419ucU9sPkd6mUwDXfZX ROwVRjUSix49Jxon7MkF0K4rMlIPNO89ipXmWUggZohJ7VVe70DYR100ujTkSuY+ Ki5ZY5VoPG8z/KbU6wg3JHw0clNBpBGR9EOIvyjQxQNC0Ye4X/Fwc0Ne87kU6jWl fUVAhwwts5cOA85UYHArsa4Zsf2iA0Lw9a1SbuvJieuas0eGa4b+ThPTR8erpPQg gPuohQWA9U0jDf1/rMmTtXFzCUvDE+6VHI2cZEFzmEg+A9j+HG7/MtbvoyRIeRCS Vcinhq5yWysRtFRauDxNydwJ8PmjHTua8QG93XO8KWEdFm8i+GFwCVNKMNhsB6C3 vC+9nIAz861wi2/FzYeN5eiaIapaeyciiQIz4DNGYDR4Y0jyjgelnxf84RSboh1m 63HaSQ+wyG0kB0rmdAXKTGZF2EwcEV5DYruWViIODNRYWJ+YJnYzbE5aAxBiKxFG kFPMkHLTXJvENCFGGOXN75R/TOYwAYvsCu3gRjCSqbP4WFqlC5+nfNaWAvUdnPXz 93uPlRfWj3TIf6c91RStpJMwaAePcmkjIOwB5Rlc87sauBvxkXbegfl/RsMa4phC Dew91kcniVdRdZAk1hkdzYoFAY8ooBZIuQ81KZf6qEdusCXfJcc= =KjgQ -----END PGP SIGNATURE-----