HIGH
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Published Mar 31, 2009
10.0
HIGHCVSS 2.0
EPSS 9.01%
Description
Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.
Affected products
No data.
OR
- 4.2.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.6.0
- 4.6.0
- 4.6.0
- 4.6.0
- 4.6.0
- 4.8.0
- 4.8.0
- 4.8.0
- 4.8.0
- 4.8.0
- 4.10.0
- 4.10.0
- 4.10.0
- 4.10.0
- 4.10.0
- 4.10.1
- 4.10.2
- 4.10.3
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.2.0
- 5.2.0
- 5.2.0
- 5.2.0
- 5.2.0
- 5.2.0
- 5.2.1
- 4.0
- 4.0
- 4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (16)
- http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/34520 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34603 third-party-advisoryx_refsource_SECUNIA
- http://trac.osgeo.org/mapserver/ticket/2944 x_refsource_CONFIRMVendor Advisory
- http://www.debian.org/security/2009/dsa-1914 vendor-advisoryx_refsource_DEBIAN
- http://www.positronsecurity.com/advisories/2009-000.html x_refsource_MISCExploit
- http://www.securityfocus.com/archive/1/502271/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/34306 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1021952 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2009-0839 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=493364 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-0836 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-0839
- https://www.cve.org/CVERecord?id=CVE-2009-0839
- https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 31, 2009
Updated Aug 7, 2024
Reserved Mar 6, 2009
Link CVE-2009-0839
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-0836 Assigner mitre
Published Mar 31, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-0836