CVE-2009-2281Improper Restriction of Operations within the Bounds of a Memory Buffer in Mapserver

Severity
10.0CRITICALNVD
EPSS
11.5%
top 6.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 2

Description

Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages4 packages

debiandebian/mapserver< mapserver 5.4.2-1 (bookworm)
Debianosgeo/mapserver< 5.4.2-1+3
NVDumn/mapserver4.0
NVDosgeo/mapserver13 versions+12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6726-5cj2-9h6f: Multiple heap-based buffer underflows in the readPostBody function in cgiutil2022-05-02
OSV
CVE-2009-2281: Multiple heap-based buffer underflows in the readPostBody function in cgiutil2009-10-23

📋Vendor Advisories

2
Debian
CVE-2009-2281: mapserver - Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c ...2009
Red Hat
mapserver: incomplete upstream fix for CVE-2009-0840

💬Community

1
Bugzilla
CVE-2009-2281 mapserver: incomplete upstream fix for CVE-2009-08402009-07-03
CVE-2009-2281 — Debian Mapserver vulnerability | cvebase