MapServer Multiple Security Vulnerabilities
BID:48720
Info
MapServer Multiple Security Vulnerabilities
| Bugtraq ID: | 48720 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2703 CVE-2011-2704 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2011 12:00AM |
| Updated: | Apr 13 2015 09:20PM |
| Credit: | Jan Lieskovsky |
| Vulnerable: |
Regents of the University of Minnesota MapServer 6.0 Regents of the University of Minnesota MapServer 5.6.4 Regents of the University of Minnesota MapServer 5.6.3 Regents of the University of Minnesota MapServer 5.4.2 Regents of the University of Minnesota MapServer 5.4.1 Regents of the University of Minnesota MapServer 5.2.3 Regents of the University of Minnesota MapServer 5.2.2 Regents of the University of Minnesota MapServer 5.2.1 Regents of the University of Minnesota MapServer 5.0.3 Regents of the University of Minnesota MapServer 4.10.6 Regents of the University of Minnesota MapServer 4.10.5 Regents of the University of Minnesota MapServer 4.10.4 Regents of the University of Minnesota MapServer 4.10.3 Regents of the University of Minnesota MapServer 4.10.2 Regents of the University of Minnesota MapServer 4.10 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Regents of the University of Minnesota MapServer 6.0.1 Regents of the University of Minnesota MapServer 5.6.7 Regents of the University of Minnesota MapServer 4.10.7 |
Exploit / POC
MapServer Multiple Security Vulnerabilities
Attackers can use a browser to exploit the SQL-injection issues.
Currently, we are not aware of any exploits for the buffer-overflow vulnerability. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Attackers can use a browser to exploit the SQL-injection issues.
Currently, we are not aware of any exploits for the buffer-overflow vulnerability. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
MapServer Multiple Security Vulnerabilities
References:
References:
- MapServer Homepage (Regents of the University of Minneso)
- [mapserver-users] MapServer 6.0.1, 5.6.7 and 4.10.7 releases with security fixes (MapServer)
- Bug 722545 - MapServer SQL injection vulnerabilities (Red Hat)
- Security Vulnerabilities - Possible SQL Injection using OGC filter encoding (MapServer)