Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.70059
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 2285-1 (mapserver)
Resumen:The remote host is missing an update to mapserver;announced via advisory DSA 2285-1.
Descripción:Summary:
The remote host is missing an update to mapserver
announced via advisory DSA 2285-1.

Vulnerability Insight:
Several vulnerabilities have been discovered in mapserver, a CGI-based
web framework to publish spatial data and interactive mapping applications.
The Common Vulnerabilities and Exposures project identifies the following
problems:

CVE-2011-2703

Several instances of insufficient escaping of user input, leading to
SQL injection attacks via OGC filter encoding (in WMS, WFS, and SOS
filters).

CVE-2011-2704

Missing length checks in the processing of OGC filter encoding that can
lead to stack-based buffer overflows and the execution of arbitrary code.


For the oldstable distribution (lenny), this problem has been fixed in
version 5.0.3-3+lenny7.

For the stable distribution (squeeze), this problem has been fixed in
version 5.6.5-2+squeeze2.

For the testing (squeeze) and unstable (sid) distributions, this problem
will be fixed soon.

Solution:
We recommend that you upgrade your mapserver packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-2703
BugTraq ID: 48720
http://www.securityfocus.com/bid/48720
Debian Security Information: DSA-2285 (Google Search)
http://www.debian.org/security/2011/dsa-2285
http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.html
http://www.openwall.com/lists/oss-security/2011/07/19/11
http://www.openwall.com/lists/oss-security/2011/07/19/14
http://www.openwall.com/lists/oss-security/2011/07/20/15
http://secunia.com/advisories/45257
http://secunia.com/advisories/45318
http://secunia.com/advisories/45368
XForce ISS Database: mapserver-multiple-sql-injection(68682)
https://exchange.xforce.ibmcloud.com/vulnerabilities/68682
Common Vulnerability Exposure (CVE) ID: CVE-2011-2704
XForce ISS Database: mapserver-ogc-bo(68719)
https://exchange.xforce.ibmcloud.com/vulnerabilities/68719
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.