CVE-2015-1592: Debian Linux
High severity, CVSS 7.5. EPSS: 74.8% chance of exploitation in the next 30 days.
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly execute arbitrary code via unspecified vectors.
Affected products
- Debian Debian Linux: version 7.0 only
- Sixapart Movable Type: from 5.2.0, before 5.2.12 (fixed in 5.2.12); from 6.0, before 6.0.7 (fixed in 6.0.7)
Published 2015-02-19. Last modified 2026-06-17.