CVE-2015-0845

NameCVE-2015-0845
DescriptionFormat string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3227-1
NVD severityhigh (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
movabletype-opensource (PTS)wheezy5.1.4+dfsg-4+deb7u3fixed
wheezy (security)5.1.4+dfsg-4+deb7u4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
movabletype-opensourcesource(unstable)(unfixed)high
movabletype-opensourcesourcesqueeze(unfixed)end-of-life
movabletype-opensourcesourcewheezy5.1.4+dfsg-4+deb7u3highDSA-3227-1

Notes

[squeeze] - movabletype-opensource <end-of-life> (Not supported in Squeeze LTS)
https://movabletype.org/news/2015/04/movable_type_608_and_5213_released_to_close_security_vulnera.html

Search for package or bug name: Reporting problems