VYPR
Unrated severityNVD Advisory· Published Mar 31, 2009· Updated Jun 16, 2026

CVE-2009-0841

CVE-2009-0841

Description

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

43
  • Osgeo/Mapserver39 versions
    cpe:2.3:a:osgeo:mapserver:4.10.0:*:*:*:*:*:*:*+ 38 more
    • cpe:2.3:a:osgeo:mapserver:4.10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.10.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.10.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.10.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.10.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.10.2:*:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.10.3:*:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.2.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.4.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.4.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.4.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.6.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.6.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.6.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.6.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.8.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.8.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.8.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.8.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:4.8.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.0.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.2.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.2.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.2.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.2.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:osgeo:mapserver:5.2.1:*:*:*:*:*:*:*
  • Umn/Mapserver3 versions
    cpe:2.3:a:umn:mapserver:4.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:umn:mapserver:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:umn:mapserver:4.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:umn:mapserver:4.0:beta2:*:*:*:*:*:*
  • Range: <4.10.4, <5.2.2

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.