DSA-2794-1 spip -- several vulnerabilities

Related Vulnerabilities: CVE-2013-4555   CVE-2013-4556   CVE-2013-4557  

Several vulnerabilities have been found in SPIP, a website engine for publishing, resulting in cross-site request forgery on logout, cross-site scripting on author page, and PHP injection. For the oldstable distribution (squeeze), these problems have been fixed in version 2.1.1-3squeeze7. For the stable distribution (wheezy), these problems have been fixed in version 2.1.17-1+deb7u2. For the testing distribution (jessie), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 2.1.24-1. For the experimental distribution, these problems have been fixed in version 3.0.12-1. We recommend that you upgrade your spip packages.

Debian Security Advisory

DSA-2794-1 spip -- several vulnerabilities

Date Reported:
10 Nov 2013
Affected Packages:
spip
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 729172.
In Mitre's CVE dictionary: CVE-2013-4555, CVE-2013-4556, CVE-2013-4557.
More information:

Several vulnerabilities have been found in SPIP, a website engine for publishing, resulting in cross-site request forgery on logout, cross-site scripting on author page, and PHP injection.

For the oldstable distribution (squeeze), these problems have been fixed in version 2.1.1-3squeeze7.

For the stable distribution (wheezy), these problems have been fixed in version 2.1.17-1+deb7u2.

For the testing distribution (jessie), these problems will be fixed soon.

For the unstable distribution (sid), these problems have been fixed in version 2.1.24-1.

For the experimental distribution, these problems have been fixed in version 3.0.12-1.

We recommend that you upgrade your spip packages.