Vulnerability Description
mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Osgeo | Mapserver | <= 4.10.5 |
| Umn | Mapserver | 4.0 |
Related Weaknesses (CWE)
References
- http://lists.osgeo.org/pipermail/mapserver-users/2010-July/066052.html
- http://marc.info/?l=oss-security&m=127973381215859&w=2
- http://marc.info/?l=oss-security&m=127973754121922&w=2
- http://trac.osgeo.org/mapserver/ticket/3485
- http://www.securityfocus.com/bid/41855
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60852
- http://lists.osgeo.org/pipermail/mapserver-users/2010-July/066052.html
- http://marc.info/?l=oss-security&m=127973381215859&w=2
- http://marc.info/?l=oss-security&m=127973754121922&w=2
- http://trac.osgeo.org/mapserver/ticket/3485
- http://www.securityfocus.com/bid/41855
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60852
FAQ
What is CVE-2010-2540?
CVE-2010-2540 is a vulnerability with a CVSS score of 10.0 (HIGH). mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to...
How severe is CVE-2010-2540?
CVE-2010-2540 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2540?
Check the references section above for vendor advisories and patch information. Affected products include: Osgeo Mapserver, Umn Mapserver.