10
CVSSv2

CVE-2009-1176

Published: 31/03/2009 Updated: 07/06/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

mapserv.c in mapserv in MapServer 4.x prior to 4.10.4 and 5.x prior to 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote malicious users to conduct buffer-overflow attacks or have unspecified other impact via a long id parameter in a query action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

osgeo mapserver 4.10.0

osgeo mapserver 4.10.2

osgeo mapserver 4.8.0

osgeo mapserver 4.6.0

osgeo mapserver 4.4.0

umn mapserver 4.0

osgeo mapserver 5.2.1

osgeo mapserver 5.2.0

osgeo mapserver 5.0.0

osgeo mapserver 4.10.3

osgeo mapserver 4.10.1

osgeo mapserver 4.2.0

Vendor Advisories

Debian Bug report logs - #523027 mapserver: multiple vulnerabilities Package: mapserver; Maintainer for mapserver is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 7 Apr 2009 22:51:06 UTC Severity: grave Tags: security Fixed i ...