MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MSMAPNOPATH and MSMAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
{
"binaries": [
{
"binary_name": "cgi-mapserver",
"binary_version": "7.0.0-9ubuntu3.1"
},
{
"binary_name": "libmapscript-java",
"binary_version": "7.0.0-9ubuntu3.1"
},
{
"binary_name": "libmapscript-perl",
"binary_version": "7.0.0-9ubuntu3.1"
},
{
"binary_name": "libmapserver-dev",
"binary_version": "7.0.0-9ubuntu3.1"
},
{
"binary_name": "libmapserver2",
"binary_version": "7.0.0-9ubuntu3.1"
},
{
"binary_name": "mapserver-bin",
"binary_version": "7.0.0-9ubuntu3.1"
},
{
"binary_name": "python-mapscript",
"binary_version": "7.0.0-9ubuntu3.1"
},
{
"binary_name": "ruby-mapscript",
"binary_version": "7.0.0-9ubuntu3.1"
}
]
}{
"binaries": [
{
"binary_name": "cgi-mapserver",
"binary_version": "7.0.7-1build2"
},
{
"binary_name": "libmapscript-java",
"binary_version": "7.0.7-1build2"
},
{
"binary_name": "libmapscript-perl",
"binary_version": "7.0.7-1build2"
},
{
"binary_name": "libmapserver-dev",
"binary_version": "7.0.7-1build2"
},
{
"binary_name": "libmapserver2",
"binary_version": "7.0.7-1build2"
},
{
"binary_name": "mapserver-bin",
"binary_version": "7.0.7-1build2"
},
{
"binary_name": "python-mapscript",
"binary_version": "7.0.7-1build2"
},
{
"binary_name": "ruby-mapscript",
"binary_version": "7.0.7-1build2"
}
]
}{
"binaries": [
{
"binary_name": "cgi-mapserver",
"binary_version": "7.4.3-2build1"
},
{
"binary_name": "libmapscript-java",
"binary_version": "7.4.3-2build1"
},
{
"binary_name": "libmapscript-perl",
"binary_version": "7.4.3-2build1"
},
{
"binary_name": "libmapserver-dev",
"binary_version": "7.4.3-2build1"
},
{
"binary_name": "libmapserver2",
"binary_version": "7.4.3-2build1"
},
{
"binary_name": "mapserver-bin",
"binary_version": "7.4.3-2build1"
},
{
"binary_name": "php-mapscript",
"binary_version": "7.4.3-2build1"
},
{
"binary_name": "php-mapscript-ng",
"binary_version": "7.4.3-2build1"
},
{
"binary_name": "python3-mapscript",
"binary_version": "7.4.3-2build1"
}
]
}{
"binaries": [
{
"binary_name": "cgi-mapserver",
"binary_version": "7.6.4-2build2"
},
{
"binary_name": "libmapscript-java",
"binary_version": "7.6.4-2build2"
},
{
"binary_name": "libmapscript-perl",
"binary_version": "7.6.4-2build2"
},
{
"binary_name": "libmapserver-dev",
"binary_version": "7.6.4-2build2"
},
{
"binary_name": "libmapserver2",
"binary_version": "7.6.4-2build2"
},
{
"binary_name": "mapserver-bin",
"binary_version": "7.6.4-2build2"
},
{
"binary_name": "python3-mapscript",
"binary_version": "7.6.4-2build2"
}
]
}{
"binaries": [
{
"binary_name": "cgi-mapserver",
"binary_version": "8.0.1-4ubuntu2"
},
{
"binary_name": "libmapscript-java",
"binary_version": "8.0.1-4ubuntu2"
},
{
"binary_name": "libmapscript-perl",
"binary_version": "8.0.1-4ubuntu2"
},
{
"binary_name": "libmapserver-dev",
"binary_version": "8.0.1-4ubuntu2"
},
{
"binary_name": "libmapserver2t64",
"binary_version": "8.0.1-4ubuntu2"
},
{
"binary_name": "mapserver-bin",
"binary_version": "8.0.1-4ubuntu2"
},
{
"binary_name": "php-mapscript-ng",
"binary_version": "8.0.1-4ubuntu2"
},
{
"binary_name": "python3-mapscript",
"binary_version": "8.0.1-4ubuntu2"
}
]
}{
"binaries": [
{
"binary_name": "cgi-mapserver",
"binary_version": "8.4.0-1build1"
},
{
"binary_name": "libmapscript-java",
"binary_version": "8.4.0-1build1"
},
{
"binary_name": "libmapscript-perl",
"binary_version": "8.4.0-1build1"
},
{
"binary_name": "libmapserver-dev",
"binary_version": "8.4.0-1build1"
},
{
"binary_name": "libmapserver2t64",
"binary_version": "8.4.0-1build1"
},
{
"binary_name": "mapserver-bin",
"binary_version": "8.4.0-1build1"
},
{
"binary_name": "php-mapscript-ng",
"binary_version": "8.4.0-1build1"
},
{
"binary_name": "python3-mapscript",
"binary_version": "8.4.0-1build1"
}
]
}{
"binaries": [
{
"binary_name": "cgi-mapserver",
"binary_version": "8.4.0-4build1"
},
{
"binary_name": "libmapscript-java",
"binary_version": "8.4.0-4build1"
},
{
"binary_name": "libmapscript-perl",
"binary_version": "8.4.0-4build1"
},
{
"binary_name": "libmapserver-dev",
"binary_version": "8.4.0-4build1"
},
{
"binary_name": "libmapserver2t64",
"binary_version": "8.4.0-4build1"
},
{
"binary_name": "mapserver-bin",
"binary_version": "8.4.0-4build1"
},
{
"binary_name": "php-mapscript-ng",
"binary_version": "8.4.0-4build1"
},
{
"binary_name": "python3-mapscript",
"binary_version": "8.4.0-4build1"
}
]
}