HIGH
mapserver: incomplete upstream fix for CVE-2009-0840
Published Oct 23, 2009
10.0
HIGHCVSS 2.0
EPSS 5.95%
Description
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.
Affected products
No data.
OR
- 4.2.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.6.0
- 4.6.0
- 4.6.0
- 4.6.0
- 4.6.0
- 4.8.0
- 4.8.0
- 4.8.0
- 4.8.0
- 4.8.0
- 4.10.0
- 4.10.0
- 4.10.0
- 4.10.0
- 4.10.0
- 4.10.1
- 4.10.2
- 4.10.3
- 4.10.4
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.2.0
- 5.2.0
- 5.2.0
- 5.2.0
- 5.2.0
- 5.2.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.0
- 5.4.1
- 4.0
- 4.0
- 4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://security.debian.org/pool/updates/main/m/mapserver/mapserver_4.10.0-5.1+etch4.diff.gz x_refsource_CONFIRMPatch
- http://security.debian.org/pool/updates/main/m/mapserver/mapserver_5.0.3-3+lenny4.diff.gz x_refsource_CONFIRMPatch
- http://trac.osgeo.org/mapserver/browser/tags/rel-5-4-2/mapserver/HISTORY.TXT x_refsource_CONFIRM
- http://trac.osgeo.org/mapserver/ticket/2943 x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1914 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2009/07/01/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/07/01/6 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2009-2281 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=509559 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-2281
- https://www.cve.org/CVERecord?id=CVE-2009-2281
| Link | Providers | Tags |
|---|---|---|
| http://security.debian.org/pool/updates/main/m/mapserver/mapserver_4.10.0-5.1+etch4.diff.gz | x_refsource_CONFIRMPatch | |
| http://security.debian.org/pool/updates/main/m/mapserver/mapserver_5.0.3-3+lenny4.diff.gz | x_refsource_CONFIRMPatch | |
| http://trac.osgeo.org/mapserver/browser/tags/rel-5-4-2/mapserver/HISTORY.TXT | x_refsource_CONFIRM | |
| http://trac.osgeo.org/mapserver/ticket/2943 | x_refsource_CONFIRM | |
| http://www.debian.org/security/2009/dsa-1914 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.openwall.com/lists/oss-security/2009/07/01/1 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2009/07/01/6 | mailing-listx_refsource_MLIST | |
| https://access.redhat.com/security/cve/CVE-2009-2281 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=509559 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-2281 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-2281 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 23, 2009
Updated Sep 16, 2024
Reserved Jul 1, 2009
Link CVE-2009-2281
CISA Vulnrichment
Updated n/a