Candidate: CVE-2009-1176 PublicDate: 2009-03-31 18:24:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1176 Description: mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other impact via a long id parameter in a query action. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_mapserver: upstream_mapserver: needs-triage dapper_mapserver: ignored (reached end-of-life) gutsy_mapserver: needed (reached end-of-life) hardy_mapserver: released (5.0.0-3ubuntu0.1) intrepid_mapserver: released (5.0.3-2ubuntu0.1) jaunty_mapserver: released (5.0.3-3ubuntu0.1) karmic_mapserver: not-affected (5.4.2-1) devel_mapserver: not-affected (5.4.2-1)