CVE-2011-2704
published 2011-08-01CVE-2011-2704: Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter…
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.22%
91.5th percentile
Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mapserver | < mapserver 6.0.1-1 (bookworm) | mapserver 6.0.1-1 (bookworm) |
| osgeo | mapserver | <= 4.10.6 | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | — | — |
| osgeo | mapserver | >= 0 < 6.0.1-1 | 6.0.1-1 |
| osgeo | mapserver | >= 0 < 6.0.1-1 | 6.0.1-1 |
| osgeo | mapserver | >= 0 < 6.0.1-1 | 6.0.1-1 |
| osgeo | mapserver | >= 0 < 6.0.1-1 | 6.0.1-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-2704: mapserver - Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allo...
vendor_debian·2011·CVSS 7.5
CVE-2011-2704 [HIGH] CVE-2011-2704: mapserver - Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allo...
Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.
Scope: local
bookworm: resolved (fixed in 6.0.1-1)
bullseye: resolved (fixed in 6.0.1-1)
forky: resolved (fixed in 6.0.1-1)
sid: resolved (fixed in 6.0.1-1)
trixie: resolved (fixed in 6.0.1-1)
GHSA
GHSA-5p55-9x25-v5f2: Stack-based buffer overflow in MapServer before 4
ghsa_unreviewed·2022-05-13
CVE-2011-2704 [HIGH] CWE-119 GHSA-5p55-9x25-v5f2: Stack-based buffer overflow in MapServer before 4
Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.
OSV
CVE-2011-2704: Stack-based buffer overflow in MapServer before 4
osv·2011-08-01·CVSS 7.5
CVE-2011-2704 [HIGH] CVE-2011-2704: Stack-based buffer overflow in MapServer before 4
Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.
No detection rules found.
No public exploits indexed.
http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.htmlhttp://secunia.com/advisories/45257http://secunia.com/advisories/45368http://trac.osgeo.org/mapserver/ticket/3903http://www.debian.org/security/2011/dsa-2285http://www.openwall.com/lists/oss-security/2011/07/19/14http://www.openwall.com/lists/oss-security/2011/07/20/15http://www.securityfocus.com/bid/48720https://bugzilla.redhat.com/show_bug.cgi?id=723293https://exchange.xforce.ibmcloud.com/vulnerabilities/68719http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.htmlhttp://secunia.com/advisories/45257http://secunia.com/advisories/45368http://trac.osgeo.org/mapserver/ticket/3903http://www.debian.org/security/2011/dsa-2285http://www.openwall.com/lists/oss-security/2011/07/19/14http://www.openwall.com/lists/oss-security/2011/07/20/15http://www.securityfocus.com/bid/48720https://bugzilla.redhat.com/show_bug.cgi?id=723293https://exchange.xforce.ibmcloud.com/vulnerabilities/68719
2011-08-01
Published