PT-2026-3385 · Mapnik · Mapnik

Oneafter

·

Published

2026-01-18

·

Updated

2026-01-18

·

CVE-2025-15537

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mapnik versions up to 4.2.0
Description A heap-based buffer overflow exists in Mapnik due to a flaw in the mapnik::dbf file::string value function within the file plugins/input/shape/dbfile.cpp. This issue can be triggered locally. The vulnerability has been publicly disclosed. The project was notified of the issue but has not yet responded.
Recommendations Versions prior to 4.2.0 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-15537

Affected Products

Mapnik