CVE-2009-0841Path Traversal in Mapserver

CWE-22Path Traversal12 documents6 sources
Severity
10.0CRITICALNVD
EPSS
0.8%
top 26.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 2

Description

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages4 packages

debiandebian/mapserver< mapserver 5.2.2-1 (bookworm)
Debianosgeo/mapserver< 5.2.2-1+3
NVDumn/mapserver4.0
NVDosgeo/mapserver11 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jrh8-99hv-m6mp: Directory traversal vulnerability in mapserv2022-05-02
OSV
CVE-2009-0841: Directory traversal vulnerability in mapserv2009-03-31

📋Vendor Advisories

8
Debian
CVE-2009-0841: mapserver - Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x befor...2009
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)

💬Community

1
Bugzilla
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)2009-04-01
CVE-2009-0841 — Path Traversal in Debian Mapserver | cvebase