Vulnerability Database

318,389

Total vulnerabilities in the database

CVE-2009-2281

Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.

  • Published: Oct 23, 2009
  • Updated: Nov 9, 2025
  • CVE: CVE-2009-2281
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
umn / mapserver 4.0 4.0.x
umn / mapserver 4.0-beta1 4.0-beta1.x
umn / mapserver 4.0-beta2 4.0-beta2.x
osgeo / mapserver 4.2.0-beta1 4.2.0-beta1.x
osgeo / mapserver 4.4.0-beta1 4.4.0-beta1.x
osgeo / mapserver 4.4.0-beta2 4.4.0-beta2.x
osgeo / mapserver 4.6.0-beta1 4.6.0-beta1.x
osgeo / mapserver 4.6.0-beta2 4.6.0-beta2.x
osgeo / mapserver 4.6.0-beta3 4.6.0-beta3.x
osgeo / mapserver 4.8.0-beta2 4.8.0-beta2.x
osgeo / mapserver 4.8.0-beta1 4.8.0-beta1.x
osgeo / mapserver 4.8.0-beta3 4.8.0-beta3.x
osgeo / mapserver 4.8.0-rc2 4.8.0-rc2.x
osgeo / mapserver 4.8.0-rc1 4.8.0-rc1.x
osgeo / mapserver 4.10.0 4.10.0.x
osgeo / mapserver 4.10.0-beta1 4.10.0-beta1.x
osgeo / mapserver 4.10.0-rc1 4.10.0-rc1.x
osgeo / mapserver 4.10.0-beta3 4.10.0-beta3.x
osgeo / mapserver 4.10.0-beta2 4.10.0-beta2.x
osgeo / mapserver 4.10.4 4.10.4.x
osgeo / mapserver 4.10.2 4.10.2.x
osgeo / mapserver 4.10.1 4.10.1.x
osgeo / mapserver 4.10.3 4.10.3.x
osgeo / mapserver 5.0.0-beta5 5.0.0-beta5.x
osgeo / mapserver 5.0.0-beta6 5.0.0-beta6.x
osgeo / mapserver 5.0.0-beta3 5.0.0-beta3.x
osgeo / mapserver 5.0.0-beta4 5.0.0-beta4.x
osgeo / mapserver 5.0.0-beta1 5.0.0-beta1.x
osgeo / mapserver 5.0.0-beta2 5.0.0-beta2.x
osgeo / mapserver 5.0.0-rc1 5.0.0-rc1.x
osgeo / mapserver 5.2.0 5.2.0.x
osgeo / mapserver 5.2.0-beta2 5.2.0-beta2.x
osgeo / mapserver 5.2.0-beta1 5.2.0-beta1.x
osgeo / mapserver 5.2.0-beta3 5.2.0-beta3.x
osgeo / mapserver 5.2.0-beta4 5.2.0-beta4.x
osgeo / mapserver 5.2.0-rc1 5.2.0-rc1.x
osgeo / mapserver 5.4.0 5.4.0.x
osgeo / mapserver 5.4.0-beta1 5.4.0-beta1.x
osgeo / mapserver 5.4.0-beta2 5.4.0-beta2.x
osgeo / mapserver 5.4.0-beta4 5.4.0-beta4.x
osgeo / mapserver 5.4.0-beta3 5.4.0-beta3.x
osgeo / mapserver 5.4.0-rc2 5.4.0-rc2.x
osgeo / mapserver 5.4.0-rc1 5.4.0-rc1.x
osgeo / mapserver 5.4.1 5.4.1.x
osgeo / mapserver 4.6.0 4.6.0.x
osgeo / mapserver 4.6.0-rc1 4.6.0-rc1.x
osgeo / mapserver 5.0.0-rc2 5.0.0-rc2.x
osgeo / mapserver 5.0.0 5.0.0.x
osgeo / mapserver 4.4.0 4.4.0.x
osgeo / mapserver 4.4.0-beta3 4.4.0-beta3.x