Vulnerability Description
Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Osgeo | Mapserver | <= 4.10.5 |
| Umn | Mapserver | 4.0 |
Related Weaknesses (CWE)
References
- http://lists.osgeo.org/pipermail/mapserver-users/2010-July/066052.htmlPatch
- http://marc.info/?l=oss-security&m=127973381215859&w=2
- http://marc.info/?l=oss-security&m=127973754121922&w=2
- http://trac.osgeo.org/mapserver/ticket/3484Patch
- http://www.securityfocus.com/bid/41855
- https://bugzilla.redhat.com/show_bug.cgi?id=617312
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60851
- http://lists.osgeo.org/pipermail/mapserver-users/2010-July/066052.htmlPatch
- http://marc.info/?l=oss-security&m=127973381215859&w=2
- http://marc.info/?l=oss-security&m=127973754121922&w=2
- http://trac.osgeo.org/mapserver/ticket/3484Patch
- http://www.securityfocus.com/bid/41855
- https://bugzilla.redhat.com/show_bug.cgi?id=617312
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60851
FAQ
What is CVE-2010-2539?
CVE-2010-2539 is a vulnerability with a CVSS score of 2.1 (LOW). Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of tempora...
How severe is CVE-2010-2539?
CVE-2010-2539 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2539?
Check the references section above for vendor advisories and patch information. Affected products include: Osgeo Mapserver, Umn Mapserver.