Release date:
Updated on:
Affected Systems:
Regents of the University of Minneso MapServer 6.x
Regents of the University of Minneso MapServer 5.x
Regents of the University of Minneso MapServer 4.x
Unaffected system:
Regents of the University of Minneso MapServer 6.0.1
Regents of the University of Minneso MapServer 5.6.7
Regents of the University of Minneso MapServer 4.10.7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 48720
Cve id: CVE-2011-2703, CVE-2011-2704
MapServer is a multi-platform program used to create an interactive map application.
MapServer has multiple SQL injection and buffer overflow vulnerabilities. Remote attackers can exploit these vulnerabilities to control applications, access or modify data, exploit potential vulnerabilities in underlying databases, or execute arbitrary code.
<* Source: Jan Lieskovsky (jlieskov@redhat.com)
Link: http://trac.osgeo.org/mapserver/ticket/3903
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Regents of the University of Minneso
------------------------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://mapserver.gis.umn.edu/