Debian alert DLA-4506-1 (mapserver)
| From: | Guilhem Moulin <guilhem@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4506-1] mapserver security update | |
| Date: | Mon, 23 Mar 2026 07:49:06 +0100 | |
| Message-ID: | <acDiYigSV1-hzHJm@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4506-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin March 23, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : mapserver Version : 7.6.2-1+deb11u1 CVE ID : CVE-2021-32062 CVE-2025-59431 Debian Bug : 988208 Vulnerabilities were found in mapserver, a CGI-based framework for Internet map services, which could lead to security controls bypass or SQL injection. CVE-2021-32062 Due to a logic flaw associated with processing map parameter, it is possible to specify an arbitrary mapfile that bypasses the `MS_MAP_NO_PATH` and `MS_MAP_PATTERN` security control checks. CVE-2025-59431 Alwin Warringa discovered that XML Filter Query directive `PropertyName` is vulnerably to Boolean-based SQL injection, allowing to manipulate backend database queries via crafted XML Filter Query directives. For Debian 11 bullseye, these problems have been fixed in version 7.6.2-1+deb11u1. We recommend that you upgrade your mapserver packages. For the detailed security status of mapserver please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mapserver Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmnA4mIACgkQ05pJnDwh pVIvBRAApuYTB5r3jv31r/4VjTe/6Evqx2bEkLDz8+MUfEK/gDE8YGwe9yKYnhMp 6kbKYHGa/TcmtaingjfL4+ptUqEwB3FK89K43jg2/mcuLzXSIR2w7r4w3IsDXqyj hnSYfUftsn50BBm7agZ1Ku0mBrNq9AkTE3y+ZdfkGoK58CA7XVB+aow8HioP7TG4 A5BEESV1wU3fHc19+EbG+FHCZsHsdE8y16dmUJgmvOq0pqUc8u8nBYDm7WXf55GE xCH6V2Ni5Q3rq7bkVQryyKOht3JdV2Cll0P8k6ELM8NQW6xXu375MSamXFXFweF9 ZnMlLSlPgRCHV7vE0sVny8d/VdLqPm6dICus7dA2SYHvzvMC1LtpWq/sE34d6H/D yfk6CEdzDms68XQgSpa7YF7hlH86DSObWf2BWkIFBapD8StDF/BZP9R/YxD+4mdp DjsfKpUcfBjYY/rXeHszdMqvGGbmmSI0+VvmTvK3YsgZmtsUBlC4oItIXY3mgXCs IiCK1AtyF0+x37Ru99TfVvvKALC1mgld85w0uK8ye85LhPuDSAVJqbQ4P6uUZyao q5fUwbYUKLG4fYEmIMnVXcJTROKrmG2SnmH/i2gSWnuVasIXMb3t+NfCyvp4xzrv gkyniTOlbHsmV2m32xBxVfs8TULyRoEv3IPmSegsZ/a0efLPJiQ= =UJhI -----END PGP SIGNATURE-----
