-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4228-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond June 14, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : spip CVE ID : CVE-2017-15736 Debian Bug : 879954 Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in cross-site scripting and PHP injection. For the oldstable distribution (jessie), this problem has been fixed in version 3.0.17-2+deb8u4. For the stable distribution (stretch), this problem has been fixed in version 3.1.4-4~deb9u1. We recommend that you upgrade your spip packages. For the detailed security status of spip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/spip Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlsiCn4ACgkQEL6Jg/PV nWQXoggApFwGkzK369kROgPl0gd6QMvtTdIZdxqS+0B7ax44BRE9jFUHI/ENMycq oWbq4jy8/8VuqsCX6PA/mKdlBtYktvj9SBH2zcEHhyyFZmZbPjtpRiY8Sd5iUrC0 k4IPTWkLLynZbUCcKs/bmMCOwPQorMfsFIFF18dVC4eiDMVlvaodKDXcvhfK/cS3 ycZH9Q+LNagKfNz8kgxoLQnL2RJJrd03WqGuU1l88xQ8nWjpg8DgMV3ZbzWLWib9 Ff6/J+AW8rKouNiBp9uuq16NhclK32tNjSIXrEmvae++Atiaj7vFHYahOhRfV7kN oC0BIlxWX5gE+20/z6v5US/aCrx9hg== =P0ev -----END PGP SIGNATURE-----