4.3
CVSSv2

CVE-2009-0842

Published: 31/03/2009 Updated: 07/06/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

mapserv in MapServer 4.x prior to 4.10.4 and 5.x prior to 5.2.2 allows remote malicious users to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

osgeo mapserver 4.10.1

osgeo mapserver 4.10.0

osgeo mapserver 4.8.0

osgeo mapserver 4.6.0

osgeo mapserver 4.4.0

osgeo mapserver 5.2.0

osgeo mapserver 5.0.0

osgeo mapserver 4.2.0

umn mapserver 4.0

osgeo mapserver 4.10.2

osgeo mapserver 4.10.3

osgeo mapserver 5.2.1

Vendor Advisories

Debian Bug report logs - #523027 mapserver: multiple vulnerabilities Package: mapserver; Maintainer for mapserver is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 7 Apr 2009 22:51:06 UTC Severity: grave Tags: security Fixed i ...
Several vulnerabilities have been discovered in mapserver, a CGI-based web framework to publish spatial data and interactive mapping applications The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0843 Missing input validation on a user supplied map queryfile name can be used by an attacker to check f ...