|
|
| |
|
| |
mapserver: multiple vulnerabilities
| Package(s): | mapserver |
CVE #(s): | CVE-2011-2703
CVE-2011-2704
|
| Created: | July 26, 2011 |
Updated: | October 30, 2012 |
| Description: |
From the Debian advisory:
CVE-2011-2703: Several instances of insufficient escaping of user input, leading to SQL injection attacks via OGC filter encoding (in WMS, WFS, and SOS filters).
CVE-2011-2704: Missing length checks in the processing of OGC filter encoding that can lead to stack-based buffer overflows and the execution of arbitrary code.
|
| Alerts: |
|
( Log in to post comments)
|
|
|