*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Marc Deslauriers 
(mdeslaur):

See:

As part of @rouault 's WFS 2.0 work he discovered a SQL injection issue
specific to WMS-Time and perhaps SOS services. It has to do with PostGIS
and time validation. Based on Even's tests for WMS-Time the
vulnerability is limited to unintended disclosure of data from the
specific table, if specific conditions are met:

WMS-Time is configured
PostGIS is used
GetFeatureInfo output formats dump all attributes (e.g. gmlitems all)
Basically you can muck with the where clause but can’t execute secondary 
commands (e.g. delete …). It may be possible to access unintended data through 
the map itself (e.g. via a label item) but that seems pretty hard. Again, SOS 
services have not been examined.

https://github.com/mapserver/mapserver/issues/4834

Fixes have been issued at: http://mapserver.org/ The issue is solved in
debian and is fixed in trusty.

** Affects: mapserver (Ubuntu)
     Importance: Undecided
         Status: Confirmed

-- 
Possible SQL Injections with postgis TIME filters
https://bugs.launchpad.net/bugs/1267616
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to