Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0839

Опубликовано: 31 мар. 2009
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:osgeo:mapserver:4.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:rc2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.1:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.2:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.3:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta6:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.0:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.0:beta2:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.08317
Низкий

10 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 16 лет назад

Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.

debian
больше 16 лет назад

Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x b ...

github
больше 3 лет назад

Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.

EPSS

Процентиль: 92%
0.08317
Низкий

10 Critical

CVSS2

Дефекты

CWE-119