CVE-2009-0839
mapserver - serveral vulnerabilities
EPSS 6.4%
Description
Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.
How to fix CVE-2009-0839
To remediate CVE-2009-0839, upgrade the affected package to a fixed version below.
- Debian/mapserver—upgrade to 5.2.2-1 or later
- Debian/mapserver—upgrade to 4.10.0-5.1+etch4 or later
Is CVE-2009-0839 being exploited?
Moderate — EPSS is 6.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 5.2.2-1
- from 0, < 4.10.0-5.1+etch4