U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2017-5522

Change History

Initial Analysis by NIST 3/16/2017 2:27:25 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:umn:mapserver:6.0.5:*:*:*:*:*:*:* (and previous)
     *cpe:2.3:a:umn:mapserver:6.2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.2.0:b1:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.2.0:b2:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.2.0:b3:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.2.0:b4:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.2.0:rc1:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.2.2:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.2.3:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.4.0:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.4.0:b1:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.4.0:b2:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.4.0:rc1:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.4.1:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.4.2:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.4.3:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:6.4.4:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:7.0.0:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:7.0.0:b1:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:7.0.0:b2:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:7.0.1:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:7.0.2:*:*:*:*:*:*:*
     *cpe:2.3:a:umn:mapserver:7.0.3:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Added CVSS V3

								
							
							
						
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
CWE-119
Changed Reference Type
http://www.debian.org/security/2017/dsa-3766 No Types Assigned
http://www.debian.org/security/2017/dsa-3766 Third Party Advisory
Changed Reference Type
http://www.mapserver.org/development/changelog/changelog-6-0-6.html#changelog-6-0-6 No Types Assigned
http://www.mapserver.org/development/changelog/changelog-6-0-6.html#changelog-6-0-6 Release Notes
Changed Reference Type
http://www.mapserver.org/development/changelog/changelog-6-2-4.html#changelog-6-2-4 No Types Assigned
http://www.mapserver.org/development/changelog/changelog-6-2-4.html#changelog-6-2-4 Release Notes
Changed Reference Type
http://www.mapserver.org/development/changelog/changelog-6-4.html#changelog-6-4-5 No Types Assigned
http://www.mapserver.org/development/changelog/changelog-6-4.html#changelog-6-4-5 Release Notes
Changed Reference Type
http://www.mapserver.org/development/changelog/changelog-7-0.html#changelog-7-0-4 No Types Assigned
http://www.mapserver.org/development/changelog/changelog-7-0.html#changelog-7-0-4 Release Notes
Changed Reference Type
https://github.com/mapserver/mapserver/commit/e52a436c0e1c5e9f7ef13428dba83194a800f4df No Types Assigned
https://github.com/mapserver/mapserver/commit/e52a436c0e1c5e9f7ef13428dba83194a800f4df Patch, Third Party Advisory
Changed Reference Type
https://lists.osgeo.org/pipermail/mapserver-dev/2017-January/015007.html No Types Assigned
https://lists.osgeo.org/pipermail/mapserver-dev/2017-January/015007.html Mailing List, Third Party Advisory