CVE-2009-0840: Buffer Overflow
Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0840?
CVE-2009-0840 has a high severity rating due to its potential to cause buffer underflows, leading to denial of service or remote code execution.
How do I fix CVE-2009-0840?
To fix CVE-2009-0840, upgrade to MapServer version 5.2.2 or later or update to the latest stable version that has addressed this vulnerability.
What systems are affected by CVE-2009-0840?
CVE-2009-0840 affects MapServer versions 4.x prior to 4.10.4 and 5.x prior to 5.2.2.
What type of vulnerability is CVE-2009-0840?
CVE-2009-0840 is classified as a heap-based buffer underflow vulnerability.
Can CVE-2009-0840 be exploited remotely?
Yes, CVE-2009-0840 can be exploited remotely by attackers through manipulated HTTP headers.