CVE-2009-0842Sensitive Information Exposure in Mapserver

Severity
4.3MEDIUMNVD
EPSS
0.8%
top 25.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 2

Description

mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

debiandebian/mapserver< mapserver 5.2.2-1 (bookworm)
Debianosgeo/mapserver< 5.2.2-1+3
NVDumn/mapserver4.0
NVDosgeo/mapserver11 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4c3c-6q2f-43vf: mapserv in MapServer 42022-05-02
OSV
CVE-2009-0842: mapserv in MapServer 42009-03-31

📋Vendor Advisories

8
Debian
CVE-2009-0842: mapserver - mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attack...2009
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)

💬Community

2
Bugzilla
mapserver: Improper handling of CGI query string fields2009-07-24
Bugzilla
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)2009-04-01
CVE-2009-0842 — Sensitive Information Exposure | cvebase