Several vulnerabilities have been found in SPIP, a website engine for publishing, resulting in cross-site request forgery on logout, cross-site scripting on author page, and PHP injection. For the oldstable distribution (squeeze), these problems have been fixed in version 2.1.1-3squeeze7. For the stable distribution (wheezy), these problems have been fixed in version 2.1.17-1+deb7u2. For the testing distribution (jessie), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 2.1.24-1. For the experimental distribution, these problems have been fixed in version 3.0.12-1. We recommend that you upgrade your spip packages.
Several vulnerabilities have been found in SPIP, a website engine for publishing, resulting in cross-site request forgery on logout, cross-site scripting on author page, and PHP injection.
For the oldstable distribution (squeeze), these problems have been fixed in version 2.1.1-3squeeze7.
For the stable distribution (wheezy), these problems have been fixed in version 2.1.17-1+deb7u2.
For the testing distribution (jessie), these problems will be fixed soon.
For the unstable distribution (sid), these problems have been fixed in version 2.1.24-1.
For the experimental distribution, these problems have been fixed in version 3.0.12-1.
We recommend that you upgrade your spip packages.