drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in MapServer
Name: |
Ausführen beliebiger Kommandos in MapServer |
|
ID: |
DSA-3766-1 |
|
Distribution: |
Debian |
|
Plattformen: |
Debian sid, Debian jessie |
|
Datum: |
Do, 19. Januar 2017, 10:28 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5522 |
|
Applikationen: |
MapServer |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
- ------------------------------------------------------------------------- Debian Security Advisory DSA-3766-1 security@debian.org https://www.debian.org/security/ Sebastien Delafond January 19, 2017 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : mapserver CVE ID : CVE-2017-5522
It was discovered that mapserver, a CGI-based framework for Internet map services, was vulnerable to a stack-based overflow. This issue allowed a remote user to crash the service, or potentially execute arbitrary code.
For the stable distribution (jessie), this problem has been fixed in version 6.4.1-5+deb8u3.
For the unstable distribution (sid), this problem has been fixed in version 7.0.4-1.
We recommend that you upgrade your mapserver packages.
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAliAe+MACgkQEL6Jg/PV nWT/DQgAuLD5VxD8r+Wl0cyTEKle+aBNGDNQlvS5Vmdp4VHqMltD0J+d0p6XVxuL 6wQeTpKmZyyaQ8XDI9VPiWUP5UtMKWAxOT5/waCMJARqUR7SkGqgWKTB8bDcs8Pl oyNRSIkJE4XM+aq14+CMjN+47kTTpbwqYIYFUtXFrqk8tDMD3Rdym18ot+vpkPgI iZmRSUFYKq5QHSjFTcFqPvkchw6xXQXI23nH8msFS4u0BBTRMVTMh3t6eiV9V0lJ xNq6B5Tq2IZb6bmsAABLsnI1WALDzv/l+fSTo8ppm++QczRzm8y1lmgN0qw6f9a0 QtbD++G6sriJurGArx7l9Awernl0XA== =KMF2 -----END PGP SIGNATURE-----
|
|
|
|