drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in SPIP (Aktualisierung)
Name: |
Mehrere Probleme in SPIP (Aktualisierung) |
|
ID: |
USN-5482-2 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 20.04 LTS |
|
Datum: |
Do, 2. März 2023, 22:07 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44123
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44122
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26846
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44120
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28984
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26847
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44118 |
|
Applikationen: |
SPIP |
|
Update von: |
Mehrere Probleme in SPIP |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============1404564267626298401== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------84OimlG0agfj0TWqEkU0Lp8X"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------84OimlG0agfj0TWqEkU0Lp8X Content-Type: multipart/mixed; boundary="------------w2BX9KWJZeyOqk7dSC2mAyGm"; protected-headers="v1" From: David Fernandez Gonzalez <david.fernandezgonzalez@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <94697fba-8db3-7a63-a7fe-da8eb17ea868@canonical.com> Subject: [USN-5482-2] SPIP vulnerabilities
--------------w2BX9KWJZeyOqk7dSC2mAyGm Content-Type: multipart/mixed; boundary="------------h65KE4BwfQHGhAVl9nvorTT9"
--------------h65KE4BwfQHGhAVl9nvorTT9 Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-5482-2 March 02, 2023
spip vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in SPIP.
Software Description: - spip: website engine for publishing
Details:
USN-5482-1 fixed several vulnerabilities in SPIP. This update provides the corresponding updates for Ubuntu 20.04 LTS for CVE-2021-44118, CVE-2021-44120, CVE-2021-44122 and CVE-2021-44123.
Original advisory details:
It was discovered that SPIP incorrectly validated inputs. An authenticated attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-28984)
Charles Fol and Théo Gordyjan discovered that SPIP is vulnerable to Cross Site Scripting (XSS). If a user were tricked into browsing a malicious SVG file, an attacker could possibly exploit this issue to execute arbitrary code. This issue was only fixed in Ubuntu 21.10. (CVE-2021-44118, CVE-2021-44120, CVE-2021-44122, CVE-2021-44123)
It was discovered that SPIP incorrectly handled certain forms. A remote authenticated editor could possibly use this issue to execute arbitrary code, and a remote unauthenticated attacker could possibly use this issue to obtain sensitive information. (CVE-2022-26846, CVE-2022-26847)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04 LTS: spip 3.2.7-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-5482-2 https://ubuntu.com/security/notices/USN-5482-1 CVE-2021-44118, CVE-2021-44120, CVE-2021-44122, CVE-2021-44123
Package Information: https://launchpad.net/ubuntu/+source/spip/3.2.7-1ubuntu0.1
--------------h65KE4BwfQHGhAVl9nvorTT9 Content-Type: application/pgp-keys; name="OpenPGP_0x86A73CCF854ECB9A.asc" Content-Disposition: attachment; filename="OpenPGP_0x86A73CCF854ECB9A.asc" Content-Description: OpenPGP public key Content-Transfer-Encoding: quoted-printable
-----BEGIN PGP PUBLIC KEY BLOCK-----
xsFNBGM0XCwBEAC/1sgU6QaxKU49T3i2BdLteX5GqAJfpwzSr2RBvr6L8W//AoUn gP8z1eiDwutJ62pTf473COZoDXTgdi7R0zT0QCbCZoHo4hVR2VHnfmxOR94XCVSE 1rvO3HF5NVLGVJl2V465y2sz2L2IWTYu1xvY/4FPhtWXLwHJmojmDbuRHF2AmX8A 6ECxYuZAcadLOuQO8mQV95YgVoWmoAjJKb1audHcLA4MRglds7jr9GgYkYWQ38Gk AM9R6DNEbRowxMBCwkj3jVz8r0kO1WOPWP0in1VvGMrlcSIgjaxW/re427CSB2LA 9QwFc+EmOE5PoNWCoAuPa+vhoo7xqTY2Qr2Wvu86PlpWS596RWFzmz5UVan5yhaB qEoEsZc7ZQbS4Qwc7x4teKhk8xQjx6lRsO6g1b4Wlm6S0PcELo1J5zwC+16MSZff eK3zuAdijyNwL2xl8XwShTUxFo/mpyB+W+zDUU8OBudsYwKYSWUbMZzferYlndcv 3atN6ZteWmuPtxHIGkkc5yChs1dsQ1ke1e9sUQA0UCdMVL4awA/LGSlo9ymTvL3Z Qwh05ujgDs09p7AkUFLLDhgS437yxzT46RqYcurDMn27kwTcfd4s2FJZVV90+Dgr z4o6lAjObZXVTsE+E2eLIxlXpfH2g3Nr/1Ipe9VZ5FetTgu32Bd3iRUQ2wARAQAB zUBEYXZpZCBGZXJuYW5kZXogR29uemFsZXogPGRhdmlkLmZlcm5hbmRlemdvbnph bGV6QGNhbm9uaWNhbC5jb20+wsGUBBMBCgA+FiEEZj5eir1e7OtcLCXYhqc8z4VO y5oFAmM0XCwCGwMFCQHhM4AFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQhqc8 z4VOy5oojA/+MNrpuhfKM5Gm5h9cKMDUysMFfULChDjzQZdkM6Gh9xBFYyidoOq2 jOAs0xEk9vb6WfB+enfxFF1jmSXPISBvdHzoI4NpAoF+tf+e2tuC6TA+hLH/VqK8 yGy9SzChihpBLze6/S3dct6ayPew2lGC+r6gUMs8XiZyTMACoZR4ywt3BolWDGpp 6za7ylFUcJOTecqVRLVDKu5+8JrXSeG/jv1QqYR1ltHdAQVxkvctOVJciOcyIz45 XJkrjFJB/kMNE6sOq2z7lMKIauFZCTaLUVrq0brY4IHtXvsa/2vN6h9bWPFor3KU hVIDhuEdjS4g3ge57+sCYrPGOHXRk+mJrqSd9T1bgLxXOP65kRUhecIRxfTovMTm iifFcAY2Q/iEAn0SMCycmi9SZngaUd+IxYXk0tCfH2Y0q12vMuuuox94+A0t05Vr 0Vej0NiBebB01a90tcJBbIVV09NrOYXDhyDvUCsuineao+CNXKoM3SaNFjOiwZgz yR1t2LcBlGVAQq/gySTE8X4WVIwVknUxcIUcOSzGDMEtd4X0qFv6A0oib/VEzuOz JVE4WqiRCXKRws5j3KMHrNi4Inac/Ew0ph60NctY50xGxQqrHhxIZG9FKb1hM+Ov cX2dy1HrLJwHf4le+Y4Yeobts8alQvJKd9IaVYZcKSt/M0JolPIPKdTOwU0EYzRc LAEQANVn81wr2CkEdUQ0l8A5gN3NOft4P6TBQBvxK+9QW9n1l/JT7Pfa1lvE62xx s+LIceFExzcq1Dfd9qnNBc39qY2XwIwNx7Gz67libTikfYhBO1gtfZ/i8GJuDjLH xOAEBnDVogkE+lnBxfZ0adfldzJ3wKMQUU7LP6+dAmF91hyJO1HOQ5eOntWhbzqW R69kRqlN7Wwd++7TbgqgiPtw6Vreu1BLlovkcImA6TZyJeD5SBN0eApBjWNZ5QCj wd0hTeCUWCu2USBApZQn76ORTIpZ4j573DVvQZq88WsN875Yu2U2pHBQtEYFT8WG Lrk5aNqDeQGw4jxGVvXwJjPOviGhhrzditvUD2L23fh7cTWSQJ6BZHoymLYQk3YZ C19ewaoNsVt1a5WxomZdPspkJLaMyiXVT0tqtcyFDb6ekEZQsziU1egsXbnjXG+l fsJmfv16k0C57EyeQLA66S7WFmjJ8dBmCx2J2WWW7etTbyU356AvZeLAiwMoGY4z ZREemM6s2hdI6eKbartF3u+aQN8k72X8hfgAM3dl0nvfhx22CaqsR0rDk3A0tYS2 QOLnkzXpulEhidStLVLkRJw59eK4vu2CYZ37923vCvTlBctYHiRudTXQUaRQYiA+ jLdWiGiYWm6wN9TybY9GO7RY06Su1aQ2BMN8w3Why3rsRJK1ABEBAAHCwXwEGAEK ACYWIQRmPl6KvV7s61wsJdiGpzzPhU7LmgUCYzRcLAIbDAUJAeEzgAAKCRCGpzzP hU7Lmq0WD/46MGGZbPLp7XFh+rlotr1GBLZ0jwudoT8kkKHRpoMKRt4OZuOBjio7 3bXh74bscu1vmS1b35QvfIfiVrNOmQ8g9794598gpS7izrC/eJfenei93dqnwAMU hEB16dEIbIevZUT3uYHNd6LgCVLdGLeauhAUZrfZ/NLvChw8+8I1Hn3Fhe5ablV7 ZfiOY/h/fC5MChBGH1izOFBkLEEeeAuaOTJKn4EYZFMitD69YGM621vCtC4jkI2g bar8O0U9t3gyAS0WbtDz4UoMhdXOY4LIUH5KvvUby1lJq+LdS39HGvgtI+Exme0P XajNpZBA/axARaUGyulxoz5+Y9InR0b4cIIMXWONVQ1pRglFEw6JrBvLcwS3SCfq LW/p1ADFcLMcYMFQmJh7IYCD14gPreDELq+gmo57qDmHzaCQbh0XZB84qhIfS/cb BFqT+0ccCLiTzAbyJeFAEu10KzLVBdUy/dysfHFevTrurObyK99MD1+6RIvNShds gEMF3sanW3yugha6XoSd855nwiJBOJD8zff201m0IH/Dxzu/EC7zfG/SqoywZnGR +N4bNLderqMXCgcyTcaLopQgExFMQoUmlRSHUGgPx5uXRkoTqY1V24c33lHp6G9G GVCAGQawnWBNaJmlqoUcbIueao+hlICYiwhG/ZIP9jUceNt1LyJi9A=3D=3D =3DRGXl -----END PGP PUBLIC KEY BLOCK-----
--------------h65KE4BwfQHGhAVl9nvorTT9--
--------------w2BX9KWJZeyOqk7dSC2mAyGm--
--------------84OimlG0agfj0TWqEkU0Lp8X Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature"
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEZj5eir1e7OtcLCXYhqc8z4VOy5oFAmQAtb4FAwAAAAAACgkQhqc8z4VOy5o5 hxAArK6yIz0jAbxe1kjCxJVmNrt7Sy/3XxWtgegjCA4LZXgo4QaQJ4RkwTR7ceaUOlQsj06AQQmC nOx5jucJU9gYM1bb6lvVeIE5NeEPuv6vRq4U9Eb9L7lEwZs/NXf9B/LBSuS78tBLV2UjY/qOqwHg vHZSNubcTXqScyDUIdaw5K8B8gdp2hrOpJAgtr6Q0W9SQ0yb+EuFNQ3of6aFceyTb9gAtPZ1//4n +TIF0nQTwuNjJtUuzLFWw1n6LkYNlrAam4Vbol4CB7rcUNFKt0e4ySuQ8mqkUIZsZUEBm1hyRSJy Mx4Gtr+yCjP+oyuRIxmG+qPpYxEz8hA8r06jnfkWLQJAiVu8qtTeJlnfq3568mLcMeeSSfZC9RPk rewqoJB4b56wPG7VnikObwGyupH+JUDzSQbxCUmT8cJ7A/PUImIx2gwKIzGPPe+0aCGyCWiWLaEy KdAtmbXCamWSdeocog0JVRPOZUxuVPSu9eiZnzKhFWlURpY3WZ/drsRSXDExT1Kfop6JEb5p+ZUw 4/o+qi6ErQFOSSMJk500jwnlAmGrnI+HQ9RVARM8vFIJOtifeZCNRgaeNiyGcugJ34hBJTLtDcnI i22TLSNKcd3lXavJeiyElIehhXmTRawmytyxIKehuYZKJ8cj1U7D7YKl9WRMgha3U6yxLeVCLEXJ 3EE= =RbfR -----END PGP SIGNATURE-----
--------------84OimlG0agfj0TWqEkU0Lp8X--
--===============1404564267626298401== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============1404564267626298401==--
|
|
|
|