REDHAT-BUG-617312: Buffer Overflow
MapServer upstream during a security audit of MapServer v5.6 source code found a potential buffer overflow in the way MapServer generated unique temporary filenames. A local attacker could use this flaw to conduct denial of service attacks.
References: [1] http://trac.osgeo.org/mapserver/ticket/3484
Upstream patch (against 5-4 SVN branch): [2] http://trac.osgeo.org/mapserver/changeset/10310
Upstream patch (against trunk): [3] http://trac.osgeo.org/mapserver/changeset/10318
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-617312?
REDHAT-BUG-617312 has been identified as a potential security vulnerability that could allow local attackers to conduct denial of service attacks.
How do I fix REDHAT-BUG-617312?
To mitigate the effects of REDHAT-BUG-617312, it is recommended to upgrade to a patched version of MapServer that addresses the buffer overflow issue.
Who is affected by REDHAT-BUG-617312?
Users of MapServer who are running vulnerable versions may be affected by the buffer overflow vulnerability described in REDHAT-BUG-617312.
What type of attack can REDHAT-BUG-617312 facilitate?
REDHAT-BUG-617312 could potentially facilitate denial of service attacks against systems running the affected MapServer software.
Is REDHAT-BUG-617312 a remote or local vulnerability?
REDHAT-BUG-617312 is a local vulnerability, meaning it can be exploited by users who have access to the system.