vendor:
MapServer
by:
NassRawI
5.5
CVSS
MEDIUM
Denial-of-Service
415
CWE
Product Name: MapServer
Affected Version From: Prior to MapServer 6.0.1
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:mapserver:mapserver
Platforms Tested: Windows XP SP2
2011
MapServer Remote Denial-of-Service Vulnerability
The vulnerability is due to a double free condition in MapServer. Attackers can exploit this issue to crash the application, denying service to legitimate users. It is possible that code execution may also be possible, but this has not been confirmed.
Mitigation:
Upgrade to MapServer version 6.0.1 or later to address this issue.