E-Mail:

Mail System Security Vulnerability in MovableType

According to MovableType there is a “… vulnerability in the mail sending packages for all Movable Type versions which allows malicious users to send email through the application to any number of arbitrary users.”

There is a new version of MovableType (3.15) available as well as a patch that fixes this problem.

I’ve applied this patch to this site as well as all Short Consulting clients’ sites utilizing MovableType.

UPDATE:

Upon sending the notification for this entry I received this error message:

Can’t use string (”ARRAY(0×898e4cc)”) as an ARRAY ref while “strict refs” in use at lib/MT/Mail.pm line 66.

The e-mail was successfully sent and nothing else appears to be broken. I’ve opened a trouble ticket with Six Apart and will hopefully be able to fix this problem soon.

9 Comments

Same here. Any luck figgering it out?

Can’t use string (”ARRAY(0×88fc5d4)”) as an ARRAY ref while “strict refs” in use at lib/MT/Mail.pm line 65.

That would be a bug in 3.15. *sigh* We’ll get it fixed. Sorry about the inconvenience.

Thanks Jay. I appreciate all of SixApart’s help with this.

Bug Discovered in MovableType 3.15

I’ve discovered a bug in MT 3.15. See this article for some of the details. The thread on the help ticket I filed with MovableType is as follows: Chris Short: Can’t use string (”ARRAY(0×898e4cc)”) as an ARRAY ref while “strict…

Bug Found In MT 3.15

I’ve discovered a bug in MT 3.15. See this article for some of the details. The thread on the help ticket I filed with MovableType is as follows:…

This Is a Test

It seems as though my plug-in upgrade to MT 3.15 has not gone as smoothly as I would have liked. Its seems now that anytime I send out notifications of a new blog posting, I get a strange message: “Can’t use string (”ARRAY(0×898e4cc)”) as an ARRAY ref …

I suspect this is also causing problems for MT 2.661. My email notifications stopped working about the same time as my webhost proactively installed the plug-in. I don’t get any error message at all. As the writer of the entry, I still get my notification of a new entry. But no one else does. Instead, my version of MT is sending out an email notification to ARRAY, which of course my server is sending back to me as undeliverable.

I’m getting the same type of error:

Can’t use string (”ARRAY(0×8a3dc40)”) as an ARRAY ref while “strict refs” in use at lib/MT/App/CMS.pm line 3749.

and my maillog shows that it’s trying to send to ARRAY@….

Same problem on our blog http://www.jointeffects.com:
Can’t use string (”ARRAY(0×898e4cc)”) as an ARRAY ref while “strict refs” in use at

Did MT solve it yet?

Thanks!

Web Site Design - May 20, 2008

Mountain Multimedia

Blogging - Dec 9, 2007

Building a Better Mousetrap (RSS Reader)

Networking - Feb 19, 2007

Software Firewalls Are Not The End-All, Be-All

58 queries / 0.858 seconds.