CVE-2009-0842: Infoleak
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0842?
CVE-2009-0842 has been classified with a medium severity rating due to its potential for information disclosure.
How do I fix CVE-2009-0842?
To fix CVE-2009-0842, upgrade your MapServer installation to version 4.10.4 or later, or 5.2.2 or later.
What versions of MapServer are affected by CVE-2009-0842?
CVE-2009-0842 affects MapServer versions 4.x before 4.10.4 and 5.x before 5.2.2.
Can CVE-2009-0842 lead to data breaches?
Yes, CVE-2009-0842 can allow remote attackers to read arbitrary file contents, potentially leading to data breaches.
Is there a workaround for CVE-2009-0842 if I can't upgrade?
A workaround for CVE-2009-0842 is to restrict user access to the application and monitor logs for any unauthorized attempts.