Lack of input sanitizing and output escaping in the CGI
mapserver's template handling and error reporting routines leads
to cross-site scripting vulnerabilities.
CVE-2007-4629
Missing bounds checking in mapserver's template handling leads to
a stack-based buffer overrun vulnerability, allowing a remote
attacker to execute arbitrary code with the privileges of the CGI
or httpd user.
For the stable distribution (etch), these problems have been fixed in
version 4.10.0-5.1+etch2.
For the unstable distribution (sid), these problems have been fixed in
version 4.10.3-1.
We recommend that you upgrade your mapserver (4.10.0-5.1+etch2) package.
Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
...
Get the latest Linux and open source security news straight to your inbox.