CVE-2015-0845

NameCVE-2015-0845
DescriptionFormat string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3227-1
NVD severityhigh (attack range: remote)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
movabletype-opensourcesource(unstable)(unfixed)high
movabletype-opensourcesourcesqueeze(unfixed)end-of-life
movabletype-opensourcesourcewheezy5.1.4+dfsg-4+deb7u3highDSA-3227-1

Notes

[squeeze] - movabletype-opensource <end-of-life> (Not supported in Squeeze LTS)
https://movabletype.org/news/2015/04/movable_type_608_and_5213_released_to_close_security_vulnera.html

Search for package or bug name: Reporting problems