Security vulnerabilities found in SPIP version 1.9.2, SPIP 2.0 and SPIP 2.1
Friday, September 23, 2011 5:00:34 PM
The flaw on the version 1.9.2 is major (sql injection) and if you have a version 1.9.2 to SPIP, we strongly recommend to update to the version 1.9.2.k.
On versions 2.0 and 2.1, the impact on the site is less important (full path disclosure), but we recommend to update in 2.0.16 and 2.1.11.
In any case you always have the opportunity to protect rapidly your site (until its complete updated) by downloading the security screen version 1.0.5 (July 26, 2011), and dropping it in your config directory (see http://www.spip.net/en_article4201.html).
Feel free to use the various resources available to the community (http://boussole.spip.org) for assistance during this updated, in particular:
- Spip-user list http://listes.rezo.net/mailman/listinfo/spip
- English Spip-user list http://listes.rezo.net/mailman/listinfo/spip-en
- Forum http://forum.spip.org/
- IRC http://spip.net/irc
Warning:
-----------------------
Note that when the version 3.0 will be released, the support for the branch 1.9.2 will be abandoned.
How to update?
-----------------------
1. spip_loader.php:
If you have already installed spip_loader, go to the address
http://YOUR_SITE_URL/spip_loader.php to install SPIP 2.1.11
2. by copying the files:
SPIP 2.1.11 is available at http://files.spip.org/spip/stable/spip.zip
SPIP 2.0.16 is available at http://files.spip.org/spip/archives/SPIP-v2-0-16.zip
SPIP 1.9.2k is available at http://files.spip.org/spip/archives/SPIP-v1-9-2k.zip
3. SVN:
If you are in the 2.1 branch just do a
svn up svn://trac.rezo.net/spip/branches/spip-2.1
the version 2.1.11 is also available in the industry:
svn://trac.rezo.net/spip/branches/spip-2-stable/
and under the tag
svn://trac.rezo.net/spip/tags/spip-2.1.11/
Post Scriptum:
-----------------------
We remind everyone that the best way to report faults or suspected faults is to send an email to spip-team@rezo.net. This is what did Lawrence Esthieux (TEHTRI-Security) and we thank him.
source: http://www.spip-contrib.net








