January 26th, 2005

Security Patch for Movable Type

Via PhotoMatt (one of the lead WordPress developers), I learned that there’s a newly discovered security flaw in Movable Type that could allow spammers to commandeer your Movable Type setup as an e-mail gateway (by futzing with the comment page, since that already sends an e-mail to the blog’s administrator).

Fortunately, there’s now a patch available (via a plugin) which works with both MT 2.661 and MT 3.14. After downloading the patch, just upload it to your plugins directory and set its permissions to 755. That’s it. (If you need an ftp client which can set permissions, FileZilla is an excellent open source ftp client which can do that.)

This work, unless otherwise expressly stated, is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>