Hi,
As agreed with the security team, I’d like to get the latest SPIP
release into stable. It fixes a stored XSS, an SQL injection SQL in
private space (so, needing credentials, yet some site may allow people
to register by themself), and a full path disclosure.
Here is the (French-only) upstream announcement.
https://blog.spip.net/Mise-a-jour-de-securite-sortie-de-SPIP-4-4-16.html
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
With the security team, we recently agreed to push the latest release
(of the 4.4 branch) via DSA instead of backporting the various fixes, so
I’m proposing to follow the same path here.
If you skip the ecrire/req/pg.exp.php rewrite (the PostgreSQL support is
still experimental), and the vendor/ directory (that is not shipped in
the binary package nor used at build time), the diffstat is “only”
64 files changed, 317 insertions(+), 76 deletions(-).
Thanks in advance for considering.
Cheers,
taffit