Candidate: CVE-2009-0839 PublicDate: 2009-03-31 18:24:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0839 Description: Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_mapserver: upstream_mapserver: needs-triage dapper_mapserver: ignored (reached end-of-life) gutsy_mapserver: needs-triage (reached end-of-life) hardy_mapserver: released (5.0.0-3ubuntu0.1) intrepid_mapserver: released (5.0.3-2ubuntu0.1) jaunty_mapserver: released (5.0.3-3ubuntu0.1) karmic_mapserver: not-affected (5.4.2-1) devel_mapserver: not-affected (5.4.2-1)