PT-2010-4093 · Mapserver · Mapserver

Published

2010-08-02

·

Updated

2021-06-07

·

CVE-2010-2540

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MapServer versions prior to 4.10.6 MapServer versions 5.x prior to 5.6.4
Description The issue is related to the improper restriction of CGI command-line arguments in mapserv.c, which were intended for debugging purposes. This allows remote attackers to have an unspecified impact via crafted arguments.
Recommendations For MapServer versions prior to 4.10.6, update to version 4.10.6 or later. For MapServer versions 5.x prior to 5.6.4, update to version 5.6.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2540
DSA-2079-1

Affected Products

Mapserver