Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 798129 (CVE-2021-32062)

Summary: <sci-geosciences/mapserver-7.6.4: unexpected map file loading (CVE-2021-32062)
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: sam, sci-geosciences
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://mapserver.org/development/changelog/changelog-7-6.html
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-24 00:46:47 UTC
CVE-2021-32062:

MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).


Please bump.
Comment 1 NATTkA bot gentoo-dev 2021-07-29 17:21:23 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-07-29 17:29:31 UTC Comment hidden (obsolete)
Comment 3 NATTkA bot gentoo-dev 2021-07-29 17:37:29 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:45:34 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:53:39 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 18:01:32 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 18:09:54 UTC
Package list is empty or all packages have requested keywords.
Comment 8 Larry the Git Cow gentoo-dev 2021-10-20 04:40:57 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d504c7f3b7fe1f51d1e84a4e59153b5c82eae727

commit d504c7f3b7fe1f51d1e84a4e59153b5c82eae727
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2021-10-20 04:40:27 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2021-10-20 04:40:32 +0000

    sci-geosciences/mapserver: add 7.6.4
    
    Bug: https://bugs.gentoo.org/798129
    Signed-off-by: Sam James <sam@gentoo.org>

 sci-geosciences/mapserver/Manifest               |   1 +
 sci-geosciences/mapserver/mapserver-7.6.4.ebuild | 286 +++++++++++++++++++++++
 2 files changed, 287 insertions(+)
Comment 9 Larry the Git Cow gentoo-dev 2022-01-31 14:17:57 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=28e6a8e2f30713703d5658eec46216b9596a76ae

commit 28e6a8e2f30713703d5658eec46216b9596a76ae
Author:     Andrew Ammerlaan <andrewammerlaan@gentoo.org>
AuthorDate: 2022-01-31 14:17:47 +0000
Commit:     Andrew Ammerlaan <andrewammerlaan@gentoo.org>
CommitDate: 2022-01-31 14:17:47 +0000

    sci-geosciences/mapserver: cleanup old
    
    Bug: https://bugs.gentoo.org/798129
    Package-Manager: Portage-3.0.30, Repoman-3.0.3
    Signed-off-by: Andrew Ammerlaan <andrewammerlaan@gentoo.org>

 sci-geosciences/mapserver/Manifest                 |   1 -
 .../mapserver/files/mapserver-7.6.2-proj8.patch    |  19 --
 .../mapserver/mapserver-7.6.2-r1.ebuild            | 291 ---------------------
 3 files changed, 311 deletions(-)
Comment 10 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-31 23:32:25 UTC
Thanks, all done!