[DSA 6435-1] spip security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6435-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
August 12, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : spip
CVE ID         : CVE-2026-66738

Several vulnerabilities were discovered in SPIP, a website engine for
publishing, which could result in remote code execution, SQL injection
and server-side request forgery.

For the stable distribution (trixie), these problems have been fixed in
version 4.4.19+dfsg-0+deb13u1.

We recommend that you upgrade your spip packages.

For the detailed security status of spip please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/spip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmp83QZfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0RJSw/+PPOnWrYCigO032l5FaQF9Q4D26jX8t9xf7FWUuKZy3w6V+P6AsFVByLJ
MauVZ6dhzraAOAPBt1CpcmixRh950z3l/ajWwhMz4l5RaRN24C79YZZkgdrosMHP
r3UOx/CYa1rCEbd/tqniiJX6E3S6lFvMZrKQz2O5GR63mL4w+MjCoOWKkkRjzNJe
kuxzRdgojTKou43HUGsSsYKS3p4K1gl8uZShYlbqv6Q+GQj1uMf3HmaXMwHYim2n
4H1UJYJMXNh2MqKMZu3/sKgZSWD7x46aoSf0gGWBOJ66uH1uuu7JhcGm+TPcaoxl
AwmBQ+YY3H1lXcykiaqxbjATQB9JYu658c8WBMGIKFjMvd7e20adzHuMujF66on+
ox9e8M382J80u/PGu2IOkkb25U091/0SJTFeOcygxzCxJbmn1Z0SV92Ay7OiVyQk
clSISUqhIXK1/8k+tzz1fwjetJb3Ib6t7J/S6jr7FzMx4xOBn9Hn969jNVRnWec0
JZLAygwDGF1kFign9gKXUpQWaH2U6bhm4xmuYCWIvcJ57+txO+Xr79I+EpZWAZPZ
V2nxhCNmXk7Z4qOoayBcn8s5e3jCQW2MSSF/sJaWeJsA9rZWmFR5Nv3Nz894qMRv
+9GUrGbhqdmfH0zGiEsIlF2OLnmGu9Q7KcKTzKQ12ZUw6q/qink=
=Nrta
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.