CVE-2009-0842 describes an information disclosure vulnerability in MapServer versions 4.x before 4.10.4 and 5.x before 5.2.2. Attackers can read partial contents of arbitrary invalid .map files by providing a full pathname in the 'map' parameter, which triggers an error message displaying the file's content. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity, resulting in partial confidentiality impact without affecting integrity or availability. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting low current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.0CPE matchmatch criteria | cpe:2.3:a:osgeo:mapserver:4.2.0:beta1:*:*:*:*:*:* | ||
4.4.0CPE matchmatch criteria | cpe:2.3:a:osgeo:mapserver:4.4.0:*:*:*:*:*:*:* | ||
4.4.0CPE matchmatch criteria | cpe:2.3:a:osgeo:mapserver:4.4.0:beta1:*:*:*:*:*:* | ||
4.4.0CPE matchmatch criteria | cpe:2.3:a:osgeo:mapserver:4.4.0:beta2:*:*:*:*:*:* | ||
4.4.0CPE matchmatch criteria | cpe:2.3:a:osgeo:mapserver:4.4.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.