Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-2263-2 moderate: Movable Type Remote Code Execution

debian
Calendar Grey December 30, 2011
Debian Logo
The security notice DSA-2263-2 regarding Movable Type in Debian highlights several vulnerabilities and security concerns that need attention.
Advisory DSA 2363-1 did not include a package for the Debian 5.0 'Lenny' suite at that time

Summary

It was discovered that Movable Type, a weblog publishing system,
contains several security vulnerabilities:

A remote attacker could execute arbitrary code in a logged-in users'
web browser.

A remote attacker could read or modify the contents in the system
under certain circumstances.

For the oldstable distribution (lenny), these problems have been fixed in
version 4.2.3-1+lenny3.

For the stable distribution (squeeze), these problems have been fixed in
version 4.3.5+dfsg-2+squeeze2.

For the testing distribution (wheezy) and for the unstable
distribution (sid), these problems have been fixed in version
4.3.6.1+dfsg-1.

We recommend that you upgrade your movabletype-opensource packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Package: movabletype-opensource
CVE ID: not yet available

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here