HIGH · 7.8

CVE-2009-0843

The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile param...

Vulnerability Description

The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OsgeoMapserver4.2.0
UmnMapserver4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0843?

CVE-2009-0843 is a vulnerability with a CVSS score of 7.8 (HIGH). The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile param...

How severe is CVE-2009-0843?

CVE-2009-0843 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0843?

Check the references section above for vendor advisories and patch information. Affected products include: Osgeo Mapserver, Umn Mapserver.