Your message dated Tue, 5 Oct 2021 19:15:50 +0200
with message-id <[email protected]>
and subject line Re: Bug#995785: Various vulnerabilities in mapserver
has caused the Debian Bug report #995785,
regarding Various vulnerabilities in mapserver
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
995785: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=995785
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: mapserver-bin
Version: 7.6.2-1

Using libFuzzer, I found various security vulnerabilities in
MapServer.  Using crashed "shapefiles", one can exploit MapServer.
One of the vulnerabilities may qualify as remote code execution,
because one can use it to overwrite arbitrary data past the end of
allocated buffers.

Here is my MapServer pull request containing fixes for the bugs found
so far:

 https://github.com/MapServer/MapServer/pull/6418

All MapServer releases are vulnerable, including older and newer
releases (Buster, Bookworm), and including the upcoming version 8 (git
main).

--- End Message ---
--- Begin Message ---
tags 995785 upstream
forwarded 995785 https://github.com/MapServer/MapServer/pull/6418
thanks

On 10/5/21 5:57 PM, Max Kellermann wrote:
> All MapServer releases are vulnerable, including older and newer
> releases (Buster, Bookworm), and including the upcoming version 8 (git
> main).

You should get CVEs for these security issues, then they will be tracked
more appropriately than with this bugreport.

Kind Regards,

Bas

-- 
 GPG Key ID: 4096R/6750F10AE88D4AF1
Fingerprint: 8182 DE41 7056 408D 6146  50D1 6750 F10A E88D 4AF1

--- End Message ---
_______________________________________________
Pkg-grass-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-grass-devel

Reply via email to