-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3227-1 security@debian.org http://www.debian.org/security/ Salvatore Bonaccorso April 15, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : movabletype-opensource CVE ID : CVE-2015-0845 John Lightsey discovered a format string injection vulnerability in the localisation of templates in Movable Type, a blogging system. An unauthenticated remote attacker could take advantage of this flaw to execute arbitrary code as the web server user. For the stable distribution (wheezy), this problem has been fixed in version 5.1.4+dfsg-4+deb7u3. We recommend that you upgrade your movabletype-opensource packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJVLrWkAAoJEAVMuPMTQ89Eh28QAI+XLCngSLbVuh1INsDiZ5q9 rACZEfaxJUM8qBttCVavqdb68H8xsA/3rk7O4HqLT67wMYoTMTI5Z6tr13klaXmc VYQONiClmTfFWPnmtyKVhuSzwgOQk06FLZKimOMs41IjS3iW/zqm0LpQOZcM1Bfu dNswRyFEx729MQ+xL5vXpnivzzdS9j5cf+3dERmziEIWwYky64Y1RC+mvkZ5Pfbc XrLTn1UIOK6ZrVb6BFJQl8ZBeqfg1HWUA/lns2OZr1BGJxsv5irNvH1vIm8PX9US Gn5rOcM5chILBftBsnXlQ+iefUBztZd8MHw4p4q86n0KBpDxgxL+jsaktb3KYNF+ Rkn24o+O80gR06gwiJBK2O/5RP9h3APBHDnDMsVeXmfuO7aimi9fEYQ163/sXvq0 FMiTLYIQUo/RhThKVu/MRs2QXsE+HN+n3je8yiX2Y8nAfIXLIhPhAoL+NKfDaG6M 0moSGiJc/qqAbK+gsL6UsDMxJmLqq+ATiC0tqh+GPt93kyJvxyVpMT4YF5lw6XnI 2HId0qJd1DhW/cfQXnuHbAXUDHgpOyht9JpA8onG33LEWWyusXHw4vd3Pznj/HE5 CDzm+IC9EXeNTY99nU4GcZlMg7gpv2croB5PkyLyNjQSoi3W2RpE3cEbMfTZnnvf IXrr8BukWFmn+Da0LlU6 =SHwM -----END PGP SIGNATURE-----