-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 23 May 2026 16:49:01 +0200
Source: spip
Architecture: source
Version: 4.4.15+dfsg-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: David Prévot <taffit@debian.org>
Changed-By: David Prévot <taffit@debian.org>
Changes:
spip (4.4.15+dfsg-0+deb13u1) trixie-security; urgency=medium
.
[ David Prévot ]
* Document CVE in previouss changelog entry
.
[ Matthieu Marcillaud ]
* build: Ajout du polyfill PHP 8.5
* build: update dependencies
* build: Version 4.4.15
+ Fix remote code execution vulnerability in the private space
[CVE-2026-8429]
+ Fix remote code execution vulnerability in the public space that is
limited to certain nginx configurations [CVE-2026-8430]
Checksums-Sha1:
1d8f949eedcc71d2c7e75e1e521c9cea33bcd757 1717 spip_4.4.15+dfsg-0+deb13u1.dsc
7d1720cce2005fcf6276f2f1780ea8df855e3747 5539832 spip_4.4.15+dfsg.orig.tar.xz
827ca6fe025a0bdd73aa26daeb88b3477142640f 88172 spip_4.4.15+dfsg-0+deb13u1.debian.tar.xz
c63ca8c2c1435778e844f99013f040af1895e1d3 8801 spip_4.4.15+dfsg-0+deb13u1_amd64.buildinfo
Checksums-Sha256:
b3a397972ce3b6e80ddc1c3d1f689949de0ae784d4e99b51cee4c51258bb94f1 1717 spip_4.4.15+dfsg-0+deb13u1.dsc
fd4d63942134f81f895ffde83d3f86b89fda45309af41eb78c6b4713f7291938 5539832 spip_4.4.15+dfsg.orig.tar.xz
4ce3035d8974827223798e1839f7cfd84d6c50f5317db3e3e5bb49443f045036 88172 spip_4.4.15+dfsg-0+deb13u1.debian.tar.xz
c1d5772296687ccc01a9322427aeb3f822edb74b1a1e2866f613b25d037355ad 8801 spip_4.4.15+dfsg-0+deb13u1_amd64.buildinfo
Files:
08355349ed6e757368d3f240a119481a 1717 web optional spip_4.4.15+dfsg-0+deb13u1.dsc
9978d50ecf649de01a87cb69baf284a7 5539832 web optional spip_4.4.15+dfsg.orig.tar.xz
63428639e2727dba14c41615cb26582a 88172 web optional spip_4.4.15+dfsg-0+deb13u1.debian.tar.xz
4d4d1cc48d7a1c44e30591d0d14da899 8801 web optional spip_4.4.15+dfsg-0+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQFGBAEBCgAwFiEEeHVNB7wJXHRI941mBYwc+UT2vTwFAmoTBloSHHRhZmZpdEBk
ZWJpYW4ub3JnAAoJEAWMHPlE9r088YcH/itcitGy1MMoi+jntYcUjKqj4qfUZvwN
1WjTPsOoseGEWsxE2gdlgLp7uMS5rjtyaF7ZnoyhK6L/TBWOPUj488d7tDWzmeek
y9qWY+PmTo7HtUvOuVJ63w7VwFQNEodORxpc962ye7cRNibOSOchAnogbz5GCYwQ
NlhXPczzzWRqgVd2QbwK1KsgRYbunxCCy+FjIUDwnx6WJ/StoNGOmtRdvzdF80Jx
8O8necWQ4Um9WoXeJBrotwF3is4YmHTKlQStdc41eyzgX1sCYG5uDhy9jAtof29C
mznMOfC8nqMiZzMrFp7a1ltst+8NS5OVPtIMDm1zgXlsbjgHVtjFpaQ=
=igXk
-----END PGP SIGNATURE-----