{"id":"UBUNTU-CVE-2013-2184","details":"Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.","modified":"2025-07-16T07:17:06.557302Z","published":"2015-03-27T14:59:00Z","withdrawn":"2025-07-18T16:42:51Z","upstream":["CVE-2013-2184"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-2184"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2013/06/14/1"},{"type":"REPORT","url":"http://perl5.git.perl.org/perl.git/commit/664f237a84176c09b20b62dbfe64dd736a7ce05e"},{"type":"REPORT","url":"http://www.movabletype.org/documentation/appendices/release-notes/movable-type-526-release-notes.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-2184"}],"affected":[{"package":{"name":"movabletype-opensource","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/movabletype-opensource@5.2.9+dfsg-1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.9+dfsg-1"}]}],"versions":["5.1.4+dfsg-5","5.2.7+dfsg-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"movabletype-opensource","binary_version":"5.2.9+dfsg-1"},{"binary_name":"movabletype-plugin-core","binary_version":"5.2.9+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2184.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}