Oval Definition:oval:org.mitre.oval:def:12430
Revision Date:2014-07-21Version:20
Title:DSA-2078-1 mapserver -- several
Description:Several vulnerabilities have been discovered in mapserver, a CGI-based web framework to publish spatial data and interactive mapping applications. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-2539 A stack-based buffer overflow in the msTmpFile function might lead to arbitrary code execution under some conditions. CVE-2010-2540 It was discovered that the CGI debug command-line arguments which are enabled by default are insecure and may allow a remote attacker to execute arbitrary code. Therefore they have been disabled by default. For the stable distribution, this problem has been fixed in version 5.0.3-3+lenny5. For the testing distribution, this problem has been fixed in version 5.6.4-1. For the unstable distribution, this problem has been fixed in version 5.6.4-1. We recommend that you upgrade your mapserver packages.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-2785
DSA-2078-1
Platform(s):Debian GNU/Linux 5.0
Product(s):mapserver
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • mapserver-doc DPKG is earlier than 5.0.3-3+lenny5
  • OR libmapscript-ruby DPKG is earlier than 5.0.3-3+lenny5
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • mapserver-bin DPKG is earlier than 5.0.3-3+lenny5
  • OR python-mapscript DPKG is earlier than 5.0.3-3+lenny5
  • OR libmapscript-ruby1.8 DPKG is earlier than 5.0.3-3+lenny5
  • OR libmapscript-ruby1.9 DPKG is earlier than 5.0.3-3+lenny5
  • OR perl-mapscript DPKG is earlier than 5.0.3-3+lenny5
  • OR php5-mapscript DPKG is earlier than 5.0.3-3+lenny5
  • OR cgi-mapserver DPKG is earlier than 5.0.3-3+lenny5
  • BACK