Candidate: CVE-2009-0842 PublicDate: 2009-03-31 18:24:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0842 Description: mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink. Ubuntu-Description: Notes: Bugs: http://trac.osgeo.org/mapserver/ticket/2941 https://launchpad.net/bugs/398814 Priority: low Discovered-by: Assigned-to: CVSS: Patches_mapserver: upstream: http://trac.osgeo.org/mapserver/changeset/8805 upstream_mapserver: released (5.2.2-1) dapper_mapserver: ignored (reached end-of-life) gutsy_mapserver: needed (reached end-of-life) hardy_mapserver: released (5.0.0-3ubuntu0.1) intrepid_mapserver: released (5.0.3-2ubuntu0.1) jaunty_mapserver: released (5.0.3-3ubuntu0.1) karmic_mapserver: not-affected devel_mapserver: not-affected