CVE-2009-0841
Published: 31 March 2009
Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.
Priority
Status
Package | Release | Status |
---|---|---|
mapserver
Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
gutsy |
Ignored
(end of life, was needs-triage)
|
|
hardy |
Released
(5.0.0-3ubuntu0.1)
|
|
intrepid |
Released
(5.0.3-2ubuntu0.1)
|
|
jaunty |
Released
(5.0.3-3ubuntu0.1)
|
|
karmic |
Not vulnerable
(5.4.2-1)
|
|
upstream |
Needs triage
|