CVE-2009-0839
EPSS 6.4%mapserver - serveral vulnerabilities
Published: 3/31/2009Modified: 4/28/2026
Description
Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.
Affected packages (2)
- Debian/mapserverfrom 0, < 5.2.2-1
- Debian/mapserverfrom 0, < 4.10.0-5.1+etch4