[Security] mapserver DoS vuln and CGI arg passing vuln

Bug #617489 reported by Brian Thomason
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mapserver (Ubuntu)
Invalid
Undecided
Unassigned
Jaunty
Fix Released
Undecided
Brian Thomason
Maverick
Invalid
Undecided
Unassigned

Bug Description

The version of mapserver in Jaunty contains two vulnerabilities:

1.) Buffer overflow in the msTmpFile function in maputil.c allows local users to cause a denial of service via vectors involving names of temporary files.
2.) mapserv.c does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.

CVE References

Changed in mapserver (Ubuntu):
assignee: nobody → Brian Thomason (brian-thomason)
Revision history for this message
Brian Thomason (brian-thomason) wrote :
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Uploaded to security queue. Thanks Brian!

visibility: private → public
Changed in mapserver (Ubuntu Maverick):
status: New → Invalid
Changed in mapserver (Ubuntu Jaunty):
assignee: nobody → Brian Thomason (brian-thomason)
status: New → Fix Committed
Changed in mapserver (Ubuntu Maverick):
assignee: Brian Thomason (brian-thomason) → nobody
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package mapserver - 5.0.3-3ubuntu0.2

---------------
mapserver (5.0.3-3ubuntu0.2) jaunty-security; urgency=low

  * SECURITY UPDATE: buffer overflow (LP: #617489)
    - debian/patches/07_mstmpfile.dpatch: Fix buffer overflow in msTmpFile
      function in maputil.c.
    - CVE-2010-2539
    - Patch provided by Debian in Lenny (DSA-2079-1)
  * SECURITY UPDATE: CGI arg passing restrictions (LP: #617489)
    - debian/patches/08_cl_debug_args.dpatch: estrict the use of CGI
      command-line arguments that were intended for debugging in mapserv.c.
    - CVE-2010-2540
    - Patch provided by Debian in Lenny (DSA-2079-1)
 -- Brian Thomason <email address hidden> Fri, 13 Aug 2010 12:55:01 -0400

Changed in mapserver (Ubuntu Jaunty):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.