LWN.net Logo

mapserver: multiple vulnerabilities

Package(s):mapserver CVE #(s):CVE-2011-2703 CVE-2011-2704
Created:July 26, 2011 Updated:October 30, 2012
Description: From the Debian advisory:

CVE-2011-2703: Several instances of insufficient escaping of user input, leading to SQL injection attacks via OGC filter encoding (in WMS, WFS, and SOS filters).

CVE-2011-2704: Missing length checks in the processing of OGC filter encoding that can lead to stack-based buffer overflows and the execution of arbitrary code.

Alerts:
Debian DSA-2285-1 2011-07-26
Fedora FEDORA-2012-16028 2012-10-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds