CVE-2010-2540
mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.83%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.83% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- osgeo/mapserver · umn/mapserver
- Source
- secalert@redhat.com
References
- http://lists.osgeo.org/pipermail/mapserver-users/2010-July/066052.html
- http://marc.info/?l=oss-security&m=127973381215859&w=2
- http://marc.info/?l=oss-security&m=127973754121922&w=2
- http://trac.osgeo.org/mapserver/ticket/3485
- http://www.securityfocus.com/bid/41855
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60852
- http://lists.osgeo.org/pipermail/mapserver-users/2010-July/066052.html
- http://marc.info/?l=oss-security&m=127973381215859&w=2
- http://marc.info/?l=oss-security&m=127973754121922&w=2
- http://trac.osgeo.org/mapserver/ticket/3485
- http://www.securityfocus.com/bid/41855
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60852
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.