CVE-2011-2703

Publication date 1 August 2011

Last updated 24 July 2024


Ubuntu priority

Description

Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.

Status

Package Ubuntu Release Status
mapserver 11.04 natty
Fixed 5.6.5-2ubuntu0.1
10.10 maverick
Fixed 5.6.5-1ubuntu0.1
10.04 LTS lucid
Fixed 5.6.1-1ubuntu1.2
8.04 LTS hardy
Fixed 5.0.0-3ubuntu0.3

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
mapserver

Access our resources on patching vulnerabilities