Candidate: CVE-2009-0843 PublicDate: 2009-03-31 18:24:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0843 Description: The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists. Ubuntu-Description: Notes: jdstrand> this can only probe for files that are not present, useless when not in combination with another attack Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: Patches_mapserver: upstream_mapserver: needs-triage dapper_mapserver: ignored (reached end-of-life) gutsy_mapserver: needed (reached end-of-life) hardy_mapserver: released (5.0.0-3ubuntu0.1) intrepid_mapserver: released (5.0.3-2ubuntu0.1) jaunty_mapserver: released (5.0.3-3ubuntu0.1) karmic_mapserver: not-affected (5.4.2-1) devel_mapserver: not-affected (5.4.2-1)