First published: Mon Sep 14 2009(Updated: )
### Withdrawn This advisory has been withdrawn as there the effects of the bug would only give the caller an incomplete view of data which they would be authorized to see. ### Original Advisory PartialBufferOutputStream2 in GeoServer before 1.6.1 and 1.7.0-beta1 attempts to flush buffer contents even when it is handling an "in memory buffer," which prevents the reporting of a service exception, with unknown impact and attack vectors.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Geoserver Geoserver | =1.3.0 | |
Geoserver Geoserver | =1.5.2 | |
Geoserver Geoserver | =1.5.0-rc4 | |
Geoserver Geoserver | =1.3.0-rc6 | |
Geoserver Geoserver | <=1.6.0 | |
Geoserver Geoserver | =1.3.0-pr1 | |
Geoserver Geoserver | =1.5.3 | |
Geoserver Geoserver | =1.4.0-m1 | |
Geoserver Geoserver | =1.6.0-beta1 | |
Geoserver Geoserver | =1.6.0-rc1 | |
Geoserver Geoserver | =1.5.1-rc1 | |
Geoserver Geoserver | =1.3.0-rc4 | |
Geoserver Geoserver | =1.3.0-rc7 | |
Geoserver Geoserver | =1.5.1 | |
Geoserver Geoserver | =1.6.0 | |
Geoserver Geoserver | =1.3.0-beta | |
Geoserver Geoserver | =1.7.0-beta1 | |
Geoserver Geoserver | =1.5.0-rc3 | |
Geoserver Geoserver | =1.3.2 | |
Geoserver Geoserver | =3.0-beta3 | |
Geoserver Geoserver | =1.6.0-rc2 | |
Geoserver Geoserver | =1.6.0-beta2 | |
Geoserver Geoserver | =1.5.0-beta2 | |
Geoserver Geoserver | =1.4.0-m0 | |
Geoserver Geoserver | =1.3.0-rc2 | |
Geoserver Geoserver | =1.6.0-rc3 | |
maven/org.geoserver.web:gs-web-app | <1.6.1 | 1.6.1 |
maven/org.geoserver:gs-main | <1.6.1 | 1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.