-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 16 Sep 2019 09:01:57 -1000 Source: spip Architecture: source Version: 3.2.5-1 Distribution: unstable Urgency: medium Maintainer: David Prévot <taffit@debian.org> Changed-By: David Prévot <taffit@debian.org> Changes: spip (3.2.5-1) unstable; urgency=medium . * Critical security fix, allowing unidentified visitor to modify any published content and execute other modifications in database * Other security fixes: - better sanitization on redirections - don’t disclose if user exists when resetting password - better error message sanitization on login page . [ ben.spip@gmail.com ] * SPIP 3.2.5 . [ David Prévot ] * Add CVE ID to previous changelog entry * Refresh patch headers * Update standards version, no changes needed. * Fix manpage section Checksums-Sha1: 82a98eb2c39b17b1b3783a9e0ccffac7fa0897e3 1481 spip_3.2.5-1.dsc 33a0490c5bf168b8604460c5174f3c3050e8dc7f 6224116 spip_3.2.5.orig.tar.xz ab6482cc4c588f9e4276e85fcb9f84637b95171c 72264 spip_3.2.5-1.debian.tar.xz 59408403e9be20b17fbbd39dd323d6acb64b9625 7743 spip_3.2.5-1_amd64.buildinfo Checksums-Sha256: 4160ca28a7ae7a9ec37848a8ddf93c5ca75f937f328df99a3c93ce206302b5ce 1481 spip_3.2.5-1.dsc d8ffa9d2bb3aed85924c523beb4e195f9dfba5c84068dce152a1990f5c4d3aff 6224116 spip_3.2.5.orig.tar.xz 27a3d86efa29a993c1ae9ca75e3ac0f5a03c8c7ffd9e6ceb8dc16adce4c0f3c3 72264 spip_3.2.5-1.debian.tar.xz c2ce88c3997712a3d96b48fa3d50b6483bb4db9003ff2d8997c7a89d4769515b 7743 spip_3.2.5-1_amd64.buildinfo Files: 09df3afacce452b51a614ce204acce5a 1481 web optional spip_3.2.5-1.dsc dbc151165178e995f67136de77a65149 6224116 web optional spip_3.2.5.orig.tar.xz e3a786636ee055f314d58486be7b70b7 72264 web optional spip_3.2.5-1.debian.tar.xz 65690f9514368bf701cb0190cb2af69b 7743 web optional spip_3.2.5-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQFGBAEBCAAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAl2AIhASHHRhZmZpdEBk ZWJpYW4ub3JnAAoJEAWMHPlE9r08PRcIAJsxgoLb7fTG8Fhk9lsSMLz48eerJC52 sMNolrNFAEybuEMVy/Io3YDI8pxCBZ3OM4epJHFUgHQqzZCSrXlu7v5ZlqiUjBlW GWIsXazyEElscVkl9ALH5wFtOGkq5FEakNzGKQHdR19hU3w5pTbqQe04roqcBRVA 5UIxBkBqSmbCqFx36kkaDMaTHsJFIB4Ij/XivzKj/LF0xeudTS49BeH1wA8DTHCp H8/QDRQnYVRWf/0wD8AkiB8QgV6BYXtQkVstrJ3A7H6fhRPSf0e6f+Lzdz0XBWW8 HNPYhUmUcn9bOgiXqLKXNSDbd8dhwE2qnm8KhqednNKtqZsZkeDgu5Y= =/3/S -----END PGP SIGNATURE-----