CVE-2011-2703
Summary
| CVE | CVE-2011-2703 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-08-01 19:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Osgeo | Mapserver | 4.10.0 | All | All | All |
| Application | Osgeo | Mapserver | 4.10.0 | beta1 | All | All |
| Application | Osgeo | Mapserver | 4.10.0 | beta2 | All | All |
| Application | Osgeo | Mapserver | 4.10.0 | beta3 | All | All |
| Application | Osgeo | Mapserver | 4.10.0 | rc1 | All | All |
| Application | Osgeo | Mapserver | 4.10.1 | All | All | All |
| Application | Osgeo | Mapserver | 4.10.2 | All | All | All |
| Application | Osgeo | Mapserver | 4.10.3 | All | All | All |
| Application | Osgeo | Mapserver | 4.10.4 | All | All | All |
| Application | Osgeo | Mapserver | 4.10.5 | All | All | All |
| Application | Osgeo | Mapserver | 4.2.0 | beta1 | All | All |
| Application | Osgeo | Mapserver | 4.4.0 | All | All | All |
| Application | Osgeo | Mapserver | 4.4.0 | beta1 | All | All |
| Application | Osgeo | Mapserver | 4.4.0 | beta2 | All | All |
| Application | Osgeo | Mapserver | 4.4.0 | beta3 | All | All |
| Application | Osgeo | Mapserver | 4.6.0 | All | All | All |
| Application | Osgeo | Mapserver | 4.6.0 | beta1 | All | All |
| Application | Osgeo | Mapserver | 4.6.0 | beta2 | All | All |
| Application | Osgeo | Mapserver | 4.6.0 | beta3 | All | All |
| Application | Osgeo | Mapserver | 4.6.0 | rc1 | All | All |
| Application | Osgeo | Mapserver | 4.8.0 | beta1 | All | All |
| Application | Osgeo | Mapserver | 4.8.0 | beta2 | All | All |
| Application | Osgeo | Mapserver | 4.8.0 | beta3 | All | All |
| Application | Osgeo | Mapserver | 4.8.0 | rc1 | All | All |
| Application | Osgeo | Mapserver | 4.8.0 | rc2 | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | All | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | beta1 | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | beta2 | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | beta3 | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | beta4 | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | beta5 | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | beta6 | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | rc1 | All | All |
| Application | Osgeo | Mapserver | 5.0.0 | rc2 | All | All |
| Application | Osgeo | Mapserver | 5.2.0 | All | All | All |
| Application | Osgeo | Mapserver | 5.2.0 | beta1 | All | All |
| Application | Osgeo | Mapserver | 5.2.0 | beta2 | All | All |
| Application | Osgeo | Mapserver | 5.2.0 | beta3 | All | All |
| Application | Osgeo | Mapserver | 5.2.0 | beta4 | All | All |
| Application | Osgeo | Mapserver | 5.2.0 | rc1 | All | All |
| Application | Osgeo | Mapserver | 5.2.1 | All | All | All |
| Application | Osgeo | Mapserver | 5.4.0 | All | All | All |
| Application | Osgeo | Mapserver | 5.4.0 | beta1 | All | All |
| Application | Osgeo | Mapserver | 5.4.0 | beta2 | All | All |
| Application | Osgeo | Mapserver | 5.4.0 | beta3 | All | All |
| Application | Osgeo | Mapserver | 5.4.0 | beta4 | All | All |
| Application | Osgeo | Mapserver | 5.4.0 | rc1 | All | All |
| Application | Osgeo | Mapserver | 5.4.0 | rc2 | All | All |
| Application | Osgeo | Mapserver | 5.4.1 | All | All | All |
| Application | Osgeo | Mapserver | 5.4.2 | All | All | All |
| Application | Osgeo | Mapserver | 5.6.0 | All | All | All |
| Application | Osgeo | Mapserver | 5.6.1 | All | All | All |
| Application | Osgeo | Mapserver | 5.6.3 | All | All | All |
| Application | Osgeo | Mapserver | All | All | All | All |
| Application | Umn | Mapserver | 5.2.2 | All | All | All |
| Application | Umn | Mapserver | 5.2.3 | All | All | All |
| Application | Umn | Mapserver | 5.6.4 | All | All | All |
| Application | Umn | Mapserver | 5.6.5 | All | All | All |
| Application | Umn | Mapserver | 5.6.6 | All | All | All |
| Application | Umn | Mapserver | 6.0.0 | All | All | All |
| Application | Umn | Mapserver | 6.0.0 | beta1 | All | All |
| Application | Umn | Mapserver | 6.0.0 | beta2 | All | All |
| Application | Umn | Mapserver | 6.0.0 | beta3 | All | All |
| Application | Umn | Mapserver | 6.0.0 | beta4 | All | All |
| Application | Umn | Mapserver | 6.0.0 | beta5 | All | All |
| Application | Umn | Mapserver | 6.0.0 | beta6 | All | All |
| Application | Umn | Mapserver | 6.0.0 | beta7 | All | All |
| Application | Umn | Mapserver | 6.0.0 | rc1 | All | All |
| Application | Umn | Mapserver | 6.0.0 | rc2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [mapserver-users] MapServer 6.0.1, 5.6.7 and 4.10.7 releases with security fixes | af854a3a-2127-422b-91ae-364da2661108 | lists.osgeo.org | Patch |
| Bug 723293 – CVE-2011-2703 CVE-2011-2704 CVE-2011-2975 MapServer (v6.0.1, v5.6.7 and v4.10.7): Multiple SQL injections and one (stack-based) buffer overflow flaw | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| MapServer SQL Injection Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-2285-1 mapserver | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Debian update for mapserver - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| oss-security - CVE Request -- MapServer -- SQL injections in OGC filter encoding and in WMS time support. | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Patch |
| MapServer Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| #3903 (Security Vulnerabilities - Possible SQL Injection using OGC filter encoding) – MapServer | af854a3a-2127-422b-91ae-364da2661108 | trac.osgeo.org | Patch |
| Bug 722545 – MapServer SQL injection vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| oss-security - Re: CVE Request -- MapServer -- Stack based buffer overflow [was: Re: Re: CVE Request -- MapServer -- SQL injections in OGC filter encoding and in WMS time support.] | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Patch |
| oss-security - CVE Request -- MapServer -- Stack based buffer overflow [was: Re: Re: CVE Request -- MapServer -- SQL injections in OGC filter encoding and in WMS time support.] | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Patch |
| MapServer Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.