CVE-2010-1678: Input Validation
Published Oct 29, 2019
·Updated
Last updated 25 August 2025
Other sources
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
— MITRE
Affected Software
4 affected componentsFixes available
OSGeo MapServer>=5.6.0<5.6.5.-2
OSGeo MapServer=5.2.0
OSGeo MapServer=5.4.0
debian/mapserver
7.6.2-18.0.0-38.4.0-4+deb13u18.6.0-1
Event History
Oct 29, 2019
CVE Published
via MITRE·08:04 PM
Data Sourced
via MITRE·08:04 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 7, 2024
Data Sourced
via Launchpad·01:45 AM
Description
Feb 17, 2026
Data Sourced
via Debian·09:33 PM
DescriptionAffected Software
Data Sourced
via Ubuntu·09:33 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2010-1678?
CVE-2010-1678 is a vulnerability in Mapserver versions 5.2, 5.4, and 5.6 before 5.6.5-2 that improperly validates symbol index values during Mapfile parsing.
2
How does CVE-2010-1678 affect Osgeo Mapserver?
CVE-2010-1678 affects Osgeo Mapserver versions 5.2, 5.4, and 5.6 before 5.6.5-2.
3
What is the severity of CVE-2010-1678?
CVE-2010-1678 has a severity value of 7.5, which is considered high.
4
Is there a fix for CVE-2010-1678?
Yes, the fix for CVE-2010-1678 is to upgrade to Mapserver version 5.6.5-2 or later.
5
Where can I find more information about CVE-2010-1678?
You can find more information about CVE-2010-1678 at the following references: [1] [2] [3]