Debian alert DSA-6448-1 (spip)
| From: | Salvatore Bonaccorso <carnil@debian.org> | |
| To: | debian-security-announce@lists.debian.org | |
| Subject: | [SECURITY] [DSA 6448-1] spip security update | |
| Date: | Tue, 18 Aug 2026 19:11:49 +0000 | |
| Message-ID: | <E1wwPDx-000000015Tq-2Owb@seger.debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6448-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso August 18, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : spip CVE ID : not yet available A vulnerability was discovered in SPIP, a website engine for publishing, which could result in unauthenticated remote code execution. For the stable distribution (trixie), this problem has been fixed in version 4.4.20+dfsg-0+deb13u1. We recommend that you upgrade your spip packages. For the detailed security status of spip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/spip Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmqErkdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Qohg/+PLWYnFnoQXaW3Rs1s8Q2pqXdW7UZBRUdkEE2DpnRr6flyFoogr7IDrMn gnMSsQHTIi205euAXeT1bcxBhL/DiMXNq495oDIL8/n8/nfldORnvHXhudav515l PZkKOag5OuxRo5pTE+HxU75x74s6bdjcZGZoHMUCZ0w+nUSPyRyzoKDSojbu9CKF ivJp44fWzZxVZeIdGh2B36ne7W4lfD/2pwoP2OlujRAYiuxoCn8Z63HX0iFWGujf BhcHfLZL2PXcsEQcjwxvdau7lrDsQ+JnNd1AXbO0yOvhpoxucVpk+8GSlJmZ09nR KL6cMP1oQE5BSBDkuXrJ+NDN2qvqvIN5SRIBYDnHAm9EUG66FqUaDjEDxUl9kYtn blwL1zzkeJA2ELZ33v+4ln/+nczg8n+QUgLC2UVlH9DUxwPJbgFrPnGaBjPxXehS vha4LcS+gKBnzVScvBD7iOl5eKyb4X8COUQD9M97ZmlrWCW92Nti41mQwsKb8vf4 iZucfgNeAeWVNi+Wyygw/f3X9nN85sfdpli3yMrm6mXQEIJnsF8NftA16VTgb+VV 9VwD26dayFHA0TZR+obkUUAo31HKt3mvI4Ye+TSxlYp//yZQyuy+LfkJPgD/rYwY ASMj5B1BcO1cBdHjQRIh01pUyhUVVAxMqYdU0QDENsh+QWGrAR4= =NaQO -----END PGP SIGNATURE-----
