• [SECURITY] [DSA 3518-1] spip security update

    From Sebastien Delafond@1:229/2 to All on Wed Mar 16 09:30:03 2016
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3518-1 [email protected] https://www.debian.org/security/ Sebastien Delafond
    March 16, 2016 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : spip
    CVE ID : CVE-2016-3153 CVE-2016-3154

    Several vulnerabilities were found in SPIP, a website engine for
    publishing, resulting in code injection.

    CVE-2016-3153

    g0uZ et sambecks, from team root-me, discovered that arbitrary PHP
    code could be injected when adding content.

    CVE-2016-3154

    Gilles Vincent discovered that deserializing untrusted content
    could result in arbitrary objects injection.

    For the oldstable distribution (wheezy), these problems have been fixed
    in version 2.1.17-1+deb7u5.

    For the stable distribution (jessie), these problems have been fixed in
    version 3.0.17-2+deb8u2.

    For the testing (stretch) and unstable (sid) distributions, these
    problems have been fixed in version 3.0.22-1.

    We recommend that you upgrade your spip packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v2

    iQEcBAEBCgAGBQJW6RkRAAoJEBC+iYPz1Z1kpzEH/292R8bZWK5tixUQCtYI9fwU Z39aJkrx5BaY3rXtC3HK+4u87lwz5FagRD8KiOUGX2FmrdtH1cEq6vmeBpTnDcz6 HAWOcRlhnO0W6uvb9jHuVZAt/fM0WPAS04ouwEtJWP7P8DzIMYG7hSp+eVdLaS4t zzKlRZeFYLfmt12OZvhigZ2JfxzaTLuaoEJiqSoKSVqm91jXJODDMvnVYk6ZyDTk Ad6iod716+CrDmXlT6+8MuNen0JHtLO7RK8fSjlFqMBcyGnIT1kflyFhgp00TYBA YanAELDj5lLnrTZa6p76KXjzda9IM6mawsc/Ij5mYT9n8MIlZ3s2/BzbCJbKuR0=
    =4zvV
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)