CVE-2010-2539: Buffer Overflow
Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files.
Other sources
MapServer upstream during a security audit of MapServer v5.6 source code found a potential buffer overflow in the way MapServer generated unique temporary filenames. A local attacker could use this flaw to conduct denial of service attacks.
References: [1] http://trac.osgeo.org/mapserver/ticket/3484
Upstream patch (against 5-4 SVN branch): [2] http://trac.osgeo.org/mapserver/changeset/10310
Upstream patch (against trunk): [3] http://trac.osgeo.org/mapserver/changeset/10318
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2539?
CVE-2010-2539 is classified as a high severity vulnerability due to its potential for denial of service attacks.
How do I fix CVE-2010-2539?
To mitigate CVE-2010-2539, upgrade to MapServer version 4.10.6 or 5.6.4 or later, which contain the patch for this vulnerability.
Who is affected by CVE-2010-2539?
CVE-2010-2539 affects various versions of MapServer, specifically versions prior to 4.10.6 and 5.x before 5.6.4.
What types of attacks can exploit CVE-2010-2539?
CVE-2010-2539 can be exploited by local users to cause a denial of service through crafting specific temporary file names.
Is CVE-2010-2539 a known vulnerability?
Yes, CVE-2010-2539 is a known and documented vulnerability that has been reported in historical security assessments.