Movable Type - vulnerability - update recommended

Discussion in 'Blogging' started by expat, Jan 27, 2005.

  1. #1
    Unusually although not using it I got a warning from a couple of my ISP's / hosts

    Anyone using should update if not already done so

    ........................................Late last night the makers of Movable Type announced that avulnerability existed in all versions of Movable Type.Movable Type is a software that is not supplied by xxxxxx, however it is very popular with our client base. If you are not using Movable Type, please ignore this email.This exploit in all versions of Movable Type allowed a malicioususer to exploit the e-mail functions of Movable Type and send unlimited spam e-mail from the targeted site.
    ....................................

    Epat

    Movable Type 3.15 released
    01.24.2005
    Version 3.15 fixes a vulnerability in the mail sending packages for all Movable Type versions in which the user has enabled comment notifications. This vulnerability allows a malicious user to send email through the application to any number of arbitrary users.

    All Movable Type users should install this update.
     
    expat, Jan 27, 2005 IP
  2. nevetS

    nevetS Evolving Dragon

    Messages:
    2,544
    Likes Received:
    211
    Best Answers:
    0
    Trophy Points:
    135
    #2
    There's a notice in your mt.cgi page when you go in to admin your site.
     
    nevetS, Jan 27, 2005 IP
  3. expat

    expat Stranger from a far land

    Messages:
    873
    Likes Received:
    18
    Best Answers:
    0
    Trophy Points:
    0
    #3
    OK, good to know, I try not to regurgitate these warnings but on some of my hosts exploits where already been traced, which obviously led to shut down of sites.

    Expat
     
    expat, Jan 28, 2005 IP