Описание
Security update for mapserver
This update for mapserver fixes the following issues:
Changes in mapserver:
-
Update to release 8.6.1
- msSLDParseRasterSymbolizer: fix potential heap buffer overflow [boo#1260869] [CVE-2026-33721]
- GetFeatureInfo with IDENTIFY CLASSAUTO: take into account SYMBOL.ANCHORPOINT
- WCS 2.0: fix issue when input raster in a rotated pole lon/lat CRS with lon_0 > 180
- UVRaster: fix WMS-Time support on layers with TILEINDEX pointing to a shapefile
- WMS GetCapabilities response: use group title and abstract when using wms_layer_group instead of GROUP
-
Update to release 8.6.0
- Add
CONNECTIONTYPE RASTERLABEL - Set
MS_LEGEND_KEYSIZE_MAXto 1000 - Add 4 new
COMPOSITE.COMPOPblending operations - Allow encryption key files to use paths relative to a mapfile
- Allow
use_default_extent_for_getfeatureto be used for OGC Features API and PostGIS - Allow append of additional query parameters for OGCAPI
- New MapServer index page
- WMS
GetFeatureInfo: add options to precisely identify points through their symbols - Add
FALLBACKparameter for theCLASSobject, to be applied if none of the previously defined classes has been applied
- Add
Список пакетов
openSUSE Leap 16.0
libjavamapscript-8.6.1-bp160.1.1
libmapserver2-8.6.1-bp160.1.1
mapserver-8.6.1-bp160.1.1
mapserver-devel-8.6.1-bp160.1.1
perl-mapscript-8.6.1-bp160.1.1
php-mapscriptng-8.6.1-bp160.1.1
python313-mapserver-8.6.1-bp160.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1260869
- SUSE CVE CVE-2026-33721 page
Описание
MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer's SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure (commonly reachable via WMS GetMap with SLD_BODY). Version 8.6.1 patches the issue.
Затронутые продукты
openSUSE Leap 16.0:libjavamapscript-8.6.1-bp160.1.1
openSUSE Leap 16.0:libmapserver2-8.6.1-bp160.1.1
openSUSE Leap 16.0:mapserver-8.6.1-bp160.1.1
openSUSE Leap 16.0:mapserver-devel-8.6.1-bp160.1.1
Ссылки
- CVE-2026-33721
- SUSE Bug 1260869