Debian Security Advisory

DLA-532-1 movabletype-opensource -- LTS security update

Date Reported:
27 Jun 2016
Affected Packages:
movabletype-opensource
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-5742.
More information:

It was discovered that there was a SQL injection vulnerability in the XML-RPC interface in MovableType, a blogging engine.

For Debian 7 Wheezy, this issue has been fixed in movabletype-opensource version 5.1.4+dfsg-4+deb7u4.

We recommend that you upgrade your movabletype-opensource packages.