Lucene search

K
cveMitreCVE-2009-1176
HistoryMar 31, 2009 - 6:24 p.m.

CVE-2009-1176

2009-03-3118:24:45
CWE-119
mitre
web.nvd.nist.gov
41
2
mapserver
cve-2009-1176
buffer-overflow
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

Low

EPSS

0.016

Percentile

87.6%

mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a โ€˜\0โ€™ character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other impact via a long id parameter in a query action.

Affected configurations

Nvd
Node
osgeomapserverMatch4.2.0beta1
OR
osgeomapserverMatch4.4.0
OR
osgeomapserverMatch4.4.0beta1
OR
osgeomapserverMatch4.4.0beta2
OR
osgeomapserverMatch4.4.0beta3
OR
osgeomapserverMatch4.6.0
OR
osgeomapserverMatch4.6.0beta1
OR
osgeomapserverMatch4.6.0beta2
OR
osgeomapserverMatch4.6.0beta3
OR
osgeomapserverMatch4.6.0rc1
OR
osgeomapserverMatch4.8.0beta1
OR
osgeomapserverMatch4.8.0beta2
OR
osgeomapserverMatch4.8.0beta3
OR
osgeomapserverMatch4.8.0rc1
OR
osgeomapserverMatch4.8.0rc2
OR
osgeomapserverMatch4.10.0
OR
osgeomapserverMatch4.10.0beta1
OR
osgeomapserverMatch4.10.0beta2
OR
osgeomapserverMatch4.10.0beta3
OR
osgeomapserverMatch4.10.0rc1
OR
osgeomapserverMatch4.10.1
OR
osgeomapserverMatch4.10.2
OR
osgeomapserverMatch4.10.3
OR
osgeomapserverMatch5.0.0
OR
osgeomapserverMatch5.0.0beta1
OR
osgeomapserverMatch5.0.0beta2
OR
osgeomapserverMatch5.0.0beta3
OR
osgeomapserverMatch5.0.0beta4
OR
osgeomapserverMatch5.0.0beta5
OR
osgeomapserverMatch5.0.0beta6
OR
osgeomapserverMatch5.0.0rc1
OR
osgeomapserverMatch5.0.0rc2
OR
osgeomapserverMatch5.2.0
OR
osgeomapserverMatch5.2.0beta1
OR
osgeomapserverMatch5.2.0beta2
OR
osgeomapserverMatch5.2.0beta3
OR
osgeomapserverMatch5.2.0beta4
OR
osgeomapserverMatch5.2.0rc1
OR
osgeomapserverMatch5.2.1
OR
umnmapserverMatch4.0
OR
umnmapserverMatch4.0beta1
OR
umnmapserverMatch4.0beta2
VendorProductVersionCPE
osgeomapserver4.2.0cpe:2.3:a:osgeo:mapserver:4.2.0:beta1:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:*:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta1:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta2:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta3:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:*:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta1:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta2:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta3:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:rc1:*:*:*:*:*:*
Rows per page:
1-10 of 421

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

Low

EPSS

0.016

Percentile

87.6%