Executive Summary

Informations
Name CVE-2010-2540 First vendor Publication 2010-08-02
Vendor Cve Last vendor Modification 2021-06-07

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2540

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:18063
 
Oval ID: oval:org.mitre.oval:def:18063
Title: DSA-2079-1 mapserver - arbitrary code execution
Description: Several vulnerabilities have been discovered in mapserver, a CGI-based web framework to publish spatial data and interactive mapping applications.
Family: unix Class: patch
Reference(s): DSA-2079-1
CVE-2010-2539
CVE-2010-2540
Version: 7
Platform(s): Debian GNU/Linux 5.0
Product(s): mapserver
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 60
Application 1

OpenVAS Exploits

Date Description
2011-08-12 Name : Fedora Update for mapserver FEDORA-2011-9555
File : nvt/gb_fedora_2011_9555_mapserver_fc14.nasl
2010-08-30 Name : Fedora Update for mapserver FEDORA-2010-12266
File : nvt/gb_fedora_2010_12266_mapserver_fc13.nasl
2010-08-21 Name : Debian Security Advisory DSA 2078-1 (mapserver)
File : nvt/deb_2078_1.nasl
2010-08-02 Name : MapServer Buffer Overflow and Unspecified Security Vulnerabilities
File : nvt/gb_mapserver_41855.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
66838 MapServer mapserv mapserv.c Crafted Debug Argument Unspecified Remote Issue

Nessus® Vulnerability Scanner

Date Description
2010-08-26 Name : The remote Fedora host is missing a security update.
File : fedora_2010-12266.nasl - Type : ACT_GATHER_INFO
2010-08-03 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2079.nasl - Type : ACT_GATHER_INFO
2010-07-27 Name : The remote web server hosts a CGI application that allows the use of insecure...
File : mapserver_insecure_cgi_args.nasl - Type : ACT_ATTACK

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/41855
CONFIRM http://trac.osgeo.org/mapserver/ticket/3485
MLIST http://lists.osgeo.org/pipermail/mapserver-users/2010-July/066052.html
http://marc.info/?l=oss-security&m=127973381215859&w=2
http://marc.info/?l=oss-security&m=127973754121922&w=2
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/60852

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
Date Informations
2021-06-26 12:06:58
  • Multiple Updates
2021-06-08 01:40:20
  • Multiple Updates
2021-06-08 01:06:58
  • Multiple Updates
2021-06-07 21:23:28
  • Multiple Updates
2021-06-02 17:23:06
  • Multiple Updates
2021-06-02 09:23:17
  • Multiple Updates
2021-06-02 01:39:41
  • Multiple Updates
2021-06-02 01:06:48
  • Multiple Updates
2021-06-01 17:23:08
  • Multiple Updates
2021-05-29 09:23:07
  • Multiple Updates
2021-05-29 01:40:12
  • Multiple Updates
2021-05-29 01:06:57
  • Multiple Updates
2021-05-29 00:23:08
  • Multiple Updates
2021-05-05 01:07:04
  • Multiple Updates
2021-05-04 12:11:42
  • Multiple Updates
2021-04-22 01:12:21
  • Multiple Updates
2020-05-23 01:42:18
  • Multiple Updates
2020-05-23 00:26:04
  • Multiple Updates
2017-08-17 09:23:03
  • Multiple Updates
2016-04-26 19:56:06
  • Multiple Updates
2014-02-17 10:56:13
  • Multiple Updates
2013-05-10 23:28:17
  • Multiple Updates