[mapserver-users] 20110713 MapServer 6.0.1, 5.6.7 and 4.10.7 releases with security fixesmailing list
http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.html CVE-2011-2975
MapServer 6.0 - '.Map' File Double-Free Remote Denial of Service
Record summary
CVE-2011-2975 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMapServer 6.0 - '.Map' File Double-Free Remote Denial of ServiceExploitDB exploitby rouaultNot analyzed1 file
References
3trac.osgeo.orgConfirmation
http://trac.osgeo.org/mapserver/ticket/3939 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-2975