Package: mapserver-bin
Version: 7.6.2-1

Using libFuzzer, I found various security vulnerabilities in
MapServer.  Using crashed "shapefiles", one can exploit MapServer.
One of the vulnerabilities may qualify as remote code execution,
because one can use it to overwrite arbitrary data past the end of
allocated buffers.

Here is my MapServer pull request containing fixes for the bugs found
so far:

 https://github.com/MapServer/MapServer/pull/6418

All MapServer releases are vulnerable, including older and newer
releases (Buster, Bookworm), and including the upcoming version 8 (git
main).

_______________________________________________
Pkg-grass-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-grass-devel

Reply via email to