CVE-2007-4629: Buffer Overflow
Buffer overflow in the processLine function in maptemplate.c in MapServer before 4.10.3 allows attackers to cause a denial of service and possibly execute arbitrary code via a mapfile with a long layer name, group name, or metadata entry name.
Other sources
Name: CVE-2007-4629 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4629 Final-Decision: Interim-Decision: Modified: Proposed: Assigned: 20070830 Category: Reference: CONFIRM:http://mapserver.gis.umn.edu/download/current/HISTORY.TXT/ Reference: CONFIRM:http://trac.osgeo.org/mapserver/ticket/2252 Reference: FRSIRT:ADV-2007-2974 Reference: URL:http://www.frsirt.com/english/advisories/2007/2974
Buffer overflow in the processLine funtion in maptemplate.c in MapServer before 4.10.3 allows attackers to cause a denial of service and possibly execute arbitrary code via a mapfile with a long layer name, group name, or metadata entry name.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4629?
CVE-2007-4629 is considered a critical vulnerability as it can lead to a denial of service and potential arbitrary code execution.
How do I fix CVE-2007-4629?
To fix CVE-2007-4629, upgrade MapServer to version 4.10.3 or later.
What systems are affected by CVE-2007-4629?
CVE-2007-4629 affects all versions of MapServer prior to 4.10.3.
Can CVE-2007-4629 be exploited remotely?
Yes, CVE-2007-4629 can be exploited remotely if an attacker can send specially crafted mapfiles.
What are the consequences of exploiting CVE-2007-4629?
Exploiting CVE-2007-4629 can lead to service interruptions and the possibility of executing arbitrary code on the vulnerable server.