Package: mapserver-bin Version: 7.6.2-1 Using libFuzzer, I found various security vulnerabilities in MapServer. Using crashed "shapefiles", one can exploit MapServer. One of the vulnerabilities may qualify as remote code execution, because one can use it to overwrite arbitrary data past the end of allocated buffers.
Here is my MapServer pull request containing fixes for the bugs found so far: https://github.com/MapServer/MapServer/pull/6418 All MapServer releases are vulnerable, including older and newer releases (Buster, Bookworm), and including the upcoming version 8 (git main). _______________________________________________ Pkg-grass-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-grass-devel
