Alerts This Week
Warning Icon 1 924
Alerts This Week
Warning Icon 1 924

Debian 9: DLA-2579-1 Critical: SPIP Cross-Site Scripting Attack Risk

debian lts
Calendar Grey March 2, 2021
Dist Debian Esm H88
Unethical actors might take advantage of SPIP in Debian to run arbitrary code or perform cross-site scripting attacks. Immediate upgrade required!
It was discovered that SPIP, a website engine for publishing, would allow a malicious user to perform cross-site scripting attacks, access sensitive information, or execute arbitra...

Summary

For Debian 9 stretch, this problem has been fixed in version
3.1.4-4~deb9u4+deb9u1.

We recommend that you upgrade your spip packages.

For the detailed security status of spip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/spip

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: spip
Version: 3.1.4-4~deb9u4+deb9u1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here