Name | CVE-2015-0845 |
Description | Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-3227-1 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
movabletype-opensource | source | squeeze | (unfixed) | end-of-life | ||
movabletype-opensource | source | wheezy | 5.1.4+dfsg-4+deb7u3 | DSA-3227-1 | ||
movabletype-opensource | source | (unstable) | (unfixed) |
[squeeze] - movabletype-opensource <end-of-life> (Not supported in Squeeze LTS)
https://movabletype.org/news/2015/04/movable_type_608_and_5213_released_to_close_security_vulnera.html