CVE-2009-1176Improper Restriction of Operations within the Bounds of a Memory Buffer in Mapserver

Severity
10.0CRITICALNVD
EPSS
2.0%
top 16.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateMay 2

Description

mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other impact via a long id parameter in a query action.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages4 packages

debiandebian/mapserver< mapserver 5.2.2-1 (bookworm)
Debianosgeo/mapserver< 5.2.2-1+3
NVDumn/mapserver4.0
NVDosgeo/mapserver11 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2mr8-vqq3-7957: mapserv2022-05-02
OSV
CVE-2009-1176: mapserv2009-03-31

📋Vendor Advisories

8
Debian
CVE-2009-1176: mapserver - mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does no...2009
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)
Red Hat
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)

💬Community

2
Bugzilla
mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177)2009-04-01
Bugzilla
CVE-2008-3143 python: Multiple integer overflows discovered by Google2008-07-11
CVE-2009-1176 — Debian Mapserver vulnerability | cvebase