An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for mapserver ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20857-1 Rating: important References: * bsc#1260869 * bsc#1266663 Cross-References: * CVE-2026-33721 * CVE-2026-45104 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for mapserver fixes the following issues: Changes in mapserver: - Update to releasee 8.6.3 * SLD parser: fix out of bounds access on SLD with only a Rule with a ElseFilter but without a symbolizer [CVE-2026-33721, boo#1260869] [CVE-2026-45104, boo#1266663] Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-287=1 Package List: - openSUSE Leap 16.0: libjavamapscript-8.6.3-bp160.1.1 libmapserver2-8.6.3-bp160.1.1 mapserver-8.6.3-bp160.1.1 mapserver-devel-8.6.3-bp160.1.1 perl-mapscript-8.6.3-bp160.1.1 php-mapscriptng-8.6.3-bp160.1.1 python313-mapserver-8.6.3-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-33721.html * https://www.suse.com/security/cve/CVE-2026-45104.html . Update for openSUSE Leap 16.0 mapserver addresses critical bugs and security issues requiring immediate attention.. openSUSE mapserver update security vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Update to mapserver-8.6.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1aa6743d40 2026-05-29 01:26:24.644293+00:00 -------------------------------------------------------------------------------- Name : mapserver Product : Fedora 43 Version : 8.6.3 Release : 1.fc43 URL : https://mapserver.org Summary : Platform for publishing spatial data and interactive mapping applications to the web Description : MapServer is an Open Source platform for publishing spatial data and interactive mapping applications to the web. -------------------------------------------------------------------------------- Update Information: Update to mapserver-8.6.3. -------------------------------------------------------------------------------- ChangeLog: * Fri May 8 2026 Sandro Mani - 8.6.3-1 - Update to 8.6.3 * Wed Apr 22 2026 Sandro Mani - 8.6.2-1 - Update to 8.6.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2477882 - CVE-2026-42030 mapserver: MapServer: Reflected Cross-Site Scripting (XSS) via unsanitized WMS parameter [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477882 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1aa6743d40' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to mapserver 8.6.1.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b5a2da2c73 2026-04-25 01:21:36.171079+00:00 -------------------------------------------------------------------------------- Name : mapserver Product : Fedora 44 Version : 8.6.1 Release : 1.fc44 URL : https://mapserver.org Summary : Platform for publishing spatial data and interactive mapping applications to the web Description : MapServer is an Open Source platform for publishing spatial data and interactive mapping applications to the web. -------------------------------------------------------------------------------- Update Information: Update to mapserver 8.6.1. -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Sandro Mani - 8.6.1-1 - Update to 8.6.1 * Sun Jan 25 2026 Elliott Sales de Andrade - 8.6.0-4 - Drop support for i686 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452126 - CVE-2026-33721 mapserver: MapServer: Denial of Service via crafted Styled Layer Descriptor [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452126 [ 2 ] Bug #2452127 - CVE-2026-33721 mapserver: MapServer: Denial of Service via crafted Styled Layer Descriptor [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452127 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b5a2da2c73' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A heap-buffer-overflow was found in mapserver, a CGI-based framework for Internet map services, which could lead to Denial of Service via crafted SLD (Styled Layer Descriptor) sent by a remote unauthenticated attacker. For Debian 11 bullseye, this problem has been fixed in version 7.6.2-1+deb11u2.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4537-1
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for mapserver ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20476-1 Rating: moderate References: * bsc#1260869 Cross-References: * CVE-2026-33721 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for mapserver fixes the following issues: Changes in mapserver: - Update to release 8.6.1 * msSLDParseRasterSymbolizer: fix potential heap buffer overflow [boo#1260869] [CVE-2026-33721] * GetFeatureInfo with IDENTIFY CLASSAUTO: take into account SYMBOL.ANCHORPOINT * WCS 2.0: fix issue when input raster in a rotated pole lon/lat CRS with lon_0> 180 * UVRaster: fix WMS-Time support on layers with TILEINDEX pointing to a shapefile * WMS GetCapabilities response: use group title and abstract when using wms_layer_group instead of GROUP - Update to release 8.6.0 * Add `CONNECTIONTYPE RASTERLABEL` * Set `MS_LEGEND_KEYSIZE_MAX` to 1000 * Add 4 new `COMPOSITE.COMPOP` blending operations * Allow encryption key files to use paths relative to a mapfile * Allow `use_default_extent_for_getfeature` to be used for OGC Features API and PostGIS * Allow append of additional query parameters for OGCAPI * New MapServer index page * WMS `GetFeatureInfo`: add options to precisely identify points through their symbols * Add `FALLBACK` parameter for the `CLASS` object, to be applied if none of the previously defined classes has been applied Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patchopenSUSE-Leap-16.0-packagehub-190=1 Package List: - openSUSE Leap 16.0: libjavamapscript-8.6.1-bp160.1.1 libmapserver2-8.6.1-bp160.1.1 mapserver-8.6.1-bp160.1.1 mapserver-devel-8.6.1-bp160.1.1 perl-mapscript-8.6.1-bp160.1.1 php-mapscriptng-8.6.1-bp160.1.1 python313-mapserver-8.6.1-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-33721.html . A security update for openSUSE addresses moderate issues in mapserver, including a heap buffer overflow. Learn more.. openSUSE mapserver update heap buffer overflow security. . LinuxSecurity.com Team
Backport fix for CVE-2026-33721.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-178c482e71 2026-04-05 00:58:39.921993+00:00 -------------------------------------------------------------------------------- Name : mapserver Product : Fedora 42 Version : 8.4.1 Release : 3.fc42 URL : http://www.mapserver.org Summary : Platform for publishing spatial data and interactive mapping applications to the web Description : MapServer is an Open Source platform for publishing spatial data and interactive mapping applications to the web. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2026-33721. -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Sandro Mani - 8.4.1-3 - Backport fix for CVE-2026-33721 * Wed Oct 1 2025 Sandro Mani - 8.4.1-2 - Sync package description with upstream text -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452127 - CVE-2026-33721 mapserver: MapServer: Denial of Service via crafted Styled Layer Descriptor [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452127 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-178c482e71' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Backport fix for CVE-2026-33721.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6d7e0a8b45 2026-04-05 00:52:10.725708+00:00 -------------------------------------------------------------------------------- Name : mapserver Product : Fedora 43 Version : 8.4.1 Release : 3.fc43 URL : http://www.mapserver.org Summary : Platform for publishing spatial data and interactive mapping applications to the web Description : MapServer is an Open Source platform for publishing spatial data and interactive mapping applications to the web. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2026-33721. -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Sandro Mani - 8.4.1-3 - Backport fix for CVE-2026-33721 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452127 - CVE-2026-33721 mapserver: MapServer: Denial of Service via crafted Styled Layer Descriptor [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452127 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6d7e0a8b45' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Vulnerabilities were found in mapserver, a CGI-based framework for Internet map services, which could lead to security controls bypass or SQL injection. CVE-2021-32062 Due to a logic flaw associated with processing map parameter, it is. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4506-1
Get the latest Linux and open source security news straight to your inbox.