CVE-2009-0840 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Mapserver
CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer18 documents6 sources
Severity
10.0CRITICALNVD
EPSS
2.7%
top 14.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 31
Latest updateMay 2
Description
Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0
Affected Packages4 packages
Patches
🔴Vulnerability Details
4📋Vendor Advisories
10Debian▶
CVE-2009-2281: mapserver - Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c ...↗2009
Debian▶
CVE-2009-0840: mapserver - Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv...↗2009
Red Hat▶
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)↗
Red Hat▶
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)↗
Red Hat▶
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)↗