CVE-2008-7227: Buffer Overflow
Withdrawn This advisory has been withdrawn as there the effects of the bug would only give the caller an incomplete view of data which they would be authorized to see.
Original Advisory PartialBufferOutputStream2 in GeoServer before 1.6.1 and 1.7.0-beta1 attempts to flush buffer contents even when it is handling an "in memory buffer," which prevents the reporting of a service exception, with unknown impact and attack vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7227?
CVE-2008-7227 has been marked as withdrawn and does not present a critical security impact.
How do I fix CVE-2008-7227?
The fix for CVE-2008-7227 involves upgrading GeoServer to version 1.6.1 or higher.
Which versions of GeoServer are affected by CVE-2008-7227?
CVE-2008-7227 affects GeoServer versions prior to 1.6.1 and 1.7.0-beta1.
Is my GeoServer installation vulnerable if it is updated?
If your GeoServer installation is updated to version 1.6.1 or above, it is not vulnerable to CVE-2008-7227.
What are the potential risks of CVE-2008-7227?
The risk associated with CVE-2008-7227 is limited to providing an incomplete view of data that users are authorized to see.