CVE-2009-0842
Publication date 31 March 2009
Last updated 24 July 2024
Ubuntu priority
Description
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mapserver | ||
Patch details
| Package | Patch details |
|---|---|
| mapserver |