It has been discovered that Slash, the Slashdot Like Automated Storytelling Homepage suffers from two vulnerabilities related to insufficient input sanitation, leading to execution of SQL commands (CVE-2008-2231) and cross-site scripting (CVE-2008-2553).
For the stable distribution (etch), these problems have been fixed in version 2.2.6-8etch1.
In the unstable distribution (sid), the slash package is currently uninstallable and will be removed soon.
We recommend that you upgrade your slash package.
MD5 checksums of the listed files are available in the original advisory.