Mail System Security Vulnerability in MovableType
- 9
- Add a Comment
According to MovableType there is a “… vulnerability in the mail sending packages for all Movable Type versions which allows malicious users to send email through the application to any number of arbitrary users.”
There is a new version of MovableType (3.15) available as well as a patch that fixes this problem.
I’ve applied this patch to this site as well as all Short Consulting clients’ sites utilizing MovableType.
UPDATE:
Upon sending the notification for this entry I received this error message:
The e-mail was successfully sent and nothing else appears to be broken. I’ve opened a trouble ticket with Six Apart and will hopefully be able to fix this problem soon.

9 Comments
JDG
January 27th, 2005
at 10:00pm
Same here. Any luck figgering it out?
Can’t use string (”ARRAY(0×88fc5d4)”) as an ARRAY ref while “strict refs” in use at lib/MT/Mail.pm line 65.
Jay Allen
January 28th, 2005
at 2:17pm
That would be a bug in 3.15. *sigh* We’ll get it fixed. Sorry about the inconvenience.
Chris Short
January 28th, 2005
at 4:00pm
Thanks Jay. I appreciate all of SixApart’s help with this.
chrisshort.net
January 28th, 2005
at 4:12pm
Bug Discovered in MovableType 3.15
I’ve discovered a bug in MT 3.15. See this article for some of the details. The thread on the help ticket I filed with MovableType is as follows: Chris Short: Can’t use string (”ARRAY(0×898e4cc)”) as an ARRAY ref while “strict…
Lockergnome's Web Developers
January 28th, 2005
at 5:54pm
Bug Found In MT 3.15
I’ve discovered a bug in MT 3.15. See this article for some of the details. The thread on the help ticket I filed with MovableType is as follows:…
PlasticMind Online
February 13th, 2005
at 2:32am
This Is a Test
It seems as though my plug-in upgrade to MT 3.15 has not gone as smoothly as I would have liked. Its seems now that anytime I send out notifications of a new blog posting, I get a strange message: “Can’t use string (”ARRAY(0×898e4cc)”) as an ARRAY ref …
Kathy
March 8th, 2005
at 11:11am
I suspect this is also causing problems for MT 2.661. My email notifications stopped working about the same time as my webhost proactively installed the plug-in. I don’t get any error message at all. As the writer of the entry, I still get my notification of a new entry. But no one else does. Instead, my version of MT is sending out an email notification to ARRAY, which of course my server is sending back to me as undeliverable.
Highway
March 23rd, 2005
at 11:24pm
I’m getting the same type of error:
Can’t use string (”ARRAY(0×8a3dc40)”) as an ARRAY ref while “strict refs” in use at lib/MT/App/CMS.pm line 3749.
and my maillog shows that it’s trying to send to ARRAY@….
z
March 28th, 2005
at 3:10pm
Same problem on our blog http://www.jointeffects.com:
Can’t use string (”ARRAY(0×898e4cc)”) as an ARRAY ref while “strict refs” in use at
Did MT solve it yet?
Thanks!