Lucene search

K
cveMitreCVE-2009-0842
HistoryMar 31, 2009 - 6:24 p.m.

CVE-2009-0842

2009-03-3118:24:45
CWE-200
mitre
web.nvd.nist.gov
47
2
security
vulnerability
mapserv
mapserver
cve-2009-0842
remote attackers
symlink
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.011

Percentile

84.4%

mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.

Affected configurations

Nvd
Node
osgeomapserverMatch4.2.0beta1
OR
osgeomapserverMatch4.4.0
OR
osgeomapserverMatch4.4.0beta1
OR
osgeomapserverMatch4.4.0beta2
OR
osgeomapserverMatch4.4.0beta3
OR
osgeomapserverMatch4.6.0
OR
osgeomapserverMatch4.6.0beta1
OR
osgeomapserverMatch4.6.0beta2
OR
osgeomapserverMatch4.6.0beta3
OR
osgeomapserverMatch4.6.0rc1
OR
osgeomapserverMatch4.8.0beta1
OR
osgeomapserverMatch4.8.0beta2
OR
osgeomapserverMatch4.8.0beta3
OR
osgeomapserverMatch4.8.0rc1
OR
osgeomapserverMatch4.8.0rc2
OR
osgeomapserverMatch4.10.0
OR
osgeomapserverMatch4.10.0beta1
OR
osgeomapserverMatch4.10.0beta2
OR
osgeomapserverMatch4.10.0beta3
OR
osgeomapserverMatch4.10.0rc1
OR
osgeomapserverMatch4.10.1
OR
osgeomapserverMatch4.10.2
OR
osgeomapserverMatch4.10.3
OR
osgeomapserverMatch5.0.0
OR
osgeomapserverMatch5.0.0beta1
OR
osgeomapserverMatch5.0.0beta2
OR
osgeomapserverMatch5.0.0beta3
OR
osgeomapserverMatch5.0.0beta4
OR
osgeomapserverMatch5.0.0beta5
OR
osgeomapserverMatch5.0.0beta6
OR
osgeomapserverMatch5.0.0rc1
OR
osgeomapserverMatch5.0.0rc2
OR
osgeomapserverMatch5.2.0
OR
osgeomapserverMatch5.2.0beta1
OR
osgeomapserverMatch5.2.0beta2
OR
osgeomapserverMatch5.2.0beta3
OR
osgeomapserverMatch5.2.0beta4
OR
osgeomapserverMatch5.2.0rc1
OR
osgeomapserverMatch5.2.1
OR
umnmapserverMatch4.0
OR
umnmapserverMatch4.0beta1
OR
umnmapserverMatch4.0beta2
VendorProductVersionCPE
osgeomapserver4.2.0cpe:2.3:a:osgeo:mapserver:4.2.0:beta1:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:*:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta1:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta2:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta3:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:*:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta1:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta2:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta3:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:rc1:*:*:*:*:*:*
Rows per page:
1-10 of 421

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.011

Percentile

84.4%