[DSA 6448-1] spip security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6448-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
August 18, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : spip
CVE ID         : not yet available

A vulnerability was discovered in SPIP, a website engine for publishing,
which could result in unauthenticated remote code execution.

For the stable distribution (trixie), this problem has been fixed in
version 4.4.20+dfsg-0+deb13u1.

We recommend that you upgrade your spip packages.

For the detailed security status of spip please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/spip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqErkdfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Qohg/+PLWYnFnoQXaW3Rs1s8Q2pqXdW7UZBRUdkEE2DpnRr6flyFoogr7IDrMn
gnMSsQHTIi205euAXeT1bcxBhL/DiMXNq495oDIL8/n8/nfldORnvHXhudav515l
PZkKOag5OuxRo5pTE+HxU75x74s6bdjcZGZoHMUCZ0w+nUSPyRyzoKDSojbu9CKF
ivJp44fWzZxVZeIdGh2B36ne7W4lfD/2pwoP2OlujRAYiuxoCn8Z63HX0iFWGujf
BhcHfLZL2PXcsEQcjwxvdau7lrDsQ+JnNd1AXbO0yOvhpoxucVpk+8GSlJmZ09nR
KL6cMP1oQE5BSBDkuXrJ+NDN2qvqvIN5SRIBYDnHAm9EUG66FqUaDjEDxUl9kYtn
blwL1zzkeJA2ELZ33v+4ln/+nczg8n+QUgLC2UVlH9DUxwPJbgFrPnGaBjPxXehS
vha4LcS+gKBnzVScvBD7iOl5eKyb4X8COUQD9M97ZmlrWCW92Nti41mQwsKb8vf4
iZucfgNeAeWVNi+Wyygw/f3X9nN85sfdpli3yMrm6mXQEIJnsF8NftA16VTgb+VV
9VwD26dayFHA0TZR+obkUUAo31HKt3mvI4Ye+TSxlYp//yZQyuy+LfkJPgD/rYwY
ASMj5B1BcO1cBdHjQRIh01pUyhUVVAxMqYdU0QDENsh+QWGrAR4=
=NaQO
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.