CVE-2009-2281

Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:osgeo:mapserver:4.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:rc2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.1:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.2:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.3:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.4:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta6:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.0:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.0:beta2:*:*:*:*:*:*

History

01 Jun 2021, 13:58

Type Values Removed Values Added
CPE cpe:2.3:a:umn:mapserver:5.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.2.0:beta2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.4.0:beta4:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10.3:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10.2:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.0.0:beta6:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.8:rc1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.6.0:beta3:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10:rc1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10:beta3:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.2.0:beta4:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10.1:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.2:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.8:beta1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.8:beta3:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.8:beta2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10.4:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10:beta2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.10.0:*:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:4.8:rc2:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.2.0:beta3:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:umn:mapserver:5.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.2:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.3:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:rc2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta6:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.1:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.4:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.10.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:beta4:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.2.0:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.6.0:beta3:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:4.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:osgeo:mapserver:5.0.0:beta5:*:*:*:*:*:*

Information

Published : 2009-10-23 18:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-2281

Mitre link : CVE-2009-2281

CVE.ORG link : CVE-2009-2281


JSON object : View

Products Affected

umn

  • mapserver

osgeo

  • mapserver
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer