Upstream information

CVE-2021-32062 at MITRE

Description

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 5
Vector AV:N/AC:L/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
CVSS v3 Scores
  National Vulnerability Database
Base Score 5.3
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact None
CVSSv3 Version 3.1
SUSE Bugzilla entry: 1185774 [NEW]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • libjavamapscript >= 7.6.3-1.2
  • libmapserver2 >= 7.6.3-1.2
  • mapserver >= 7.6.3-1.2
  • mapserver-devel >= 7.6.3-1.2
  • perl-mapscript >= 7.6.3-1.2
  • php-mapscript >= 7.6.3-1.2
  • python-mapscript >= 7.6.3-1.2
Patchnames:
openSUSE Tumbleweed GA libjavamapscript-7.6.3-1.2


SUSE Timeline for this CVE

CVE page created: Thu May 6 19:01:48 2021
CVE page last modified: Wed Oct 26 23:16:09 2022