• [SECURITY] [DSA 3227-1] movabletype-opensource security update

    From Salvatore Bonaccorso@1:229/2 to All on Wed Apr 15 21:10:02 2015
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3227-1 [email protected] http://www.debian.org/security/ Salvatore Bonaccorso
    April 15, 2015 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : movabletype-opensource
    CVE ID : CVE-2015-0845

    John Lightsey discovered a format string injection vulnerability in the localisation of templates in Movable Type, a blogging system. An unauthenticated remote attacker could take advantage of this flaw to
    execute arbitrary code as the web server user.

    For the stable distribution (wheezy), this problem has been fixed in
    version 5.1.4+dfsg-4+deb7u3.

    We recommend that you upgrade your movabletype-opensource packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCgAGBQJVLrWkAAoJEAVMuPMTQ89Eh28QAI+XLCngSLbVuh1INsDiZ5q9 rACZEfaxJUM8qBttCVavqdb68H8xsA/3rk7O4HqLT67wMYoTMTI5Z6tr13klaXmc VYQONiClmTfFWPnmtyKVhuSzwgOQk06FLZKimOMs41IjS3iW/zqm0LpQOZcM1Bfu dNswRyFEx729MQ+xL5vXpnivzzdS9j5cf+3dERmziEIWwYky64Y1RC+mvkZ5Pfbc XrLTn1UIOK6ZrVb6BFJQl8ZBeqfg1HWUA/lns2OZr1BGJxsv5irNvH1vIm8PX9US Gn5rOcM5chILBftBsnXlQ+iefUBztZd8MHw4p4q86n0KBpDxgxL+jsaktb3KYNF+ Rkn24o+O80gR06gwiJBK2O/5RP9h3APBHDnDMsVeXmfuO7aimi9fEYQ163/sXvq0 FMiTLYIQUo/RhThKVu/MRs2QXsE+HN+n3je8yiX2Y8nAfIXLIhPhAoL+NKfDaG6M 0moSGiJc/qqAbK+gsL6UsDMxJmLqq+ATiC0tqh+GPt93kyJvxyVpMT4YF5lw6XnI 2HId0qJd1DhW/cfQXnuHbAXUDHgpOyht9JpA8onG33LEWWyusXHw4vd3Pznj/HE5 CDzm+IC9EXeNTY99nU4GcZlMg7gpv2croB5PkyLyNjQSoi3W2RpE3cEbMfTZnnvf IXrr8BukWFmn+Da0LlU6
    =SHwM
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)