Bug ID 1185774
Summary VUL-0: CVE-2021-32062: mapserver: flaw in CGI mapfile loading that makes it possible to bypass security controls
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/283589/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Development
Assignee dassau@gbd-consult.de
Reporter gianluca.gabrielli@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2021-32062

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before
7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the
MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the
locations from which a mapfile may be loaded (with MapServer CGI).

References:
https://mapserver.org/development/changelog/changelog-7-6.html
https://mapserver.org/development/changelog/changelog-7-0.html
https://mapserver.org/development/changelog/changelog-7-4.html
https://mapserver.org/development/changelog/changelog-7-2.html

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1957872
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-32062
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32062
https://mapserver.org/development/changelog/changelog-7-2.html
https://mapserver.org/development/changelog/changelog-7-0.html
https://mapserver.org/development/changelog/changelog-7-6.html
https://mapserver.org/development/changelog/changelog-7-4.html


You are receiving this mail because: