Bug#734565: mapserver: CVE-2013-7262

2014-01-09 Thread Salvatore Bonaccorso
Hi Sebastiaan, On Wed, Jan 08, 2014 at 11:15:56PM +0100, Sebastiaan Couwenberg wrote: > Hi Salvatore, > > On 01/08/2014 10:09 AM, Salvatore Bonaccorso wrote: > > On Wed, Jan 08, 2014 at 08:40:35AM +0100, Sebastiaan Couwenberg wrote: > >> On 01/08/2014 08:25 AM, Salvatore Bonaccorso wrote: > >>> I

Bug#734565: mapserver: CVE-2013-7262

2014-01-08 Thread Sebastiaan Couwenberg
Hi Salvatore, On 01/08/2014 10:09 AM, Salvatore Bonaccorso wrote: > On Wed, Jan 08, 2014 at 08:40:35AM +0100, Sebastiaan Couwenberg wrote: >> On 01/08/2014 08:25 AM, Salvatore Bonaccorso wrote: >>> If you fix the vulnerability please also make sure to include the >>> CVE (Common Vulnerabilities &

Bug#734565: mapserver: CVE-2013-7262

2014-01-08 Thread Salvatore Bonaccorso
Hi Bas, On Wed, Jan 08, 2014 at 08:40:35AM +0100, Sebastiaan Couwenberg wrote: > On 01/08/2014 08:25 AM, Salvatore Bonaccorso wrote: > > If you fix the vulnerability please also make sure to include the > > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > The new mapserver

Bug#734565: mapserver: CVE-2013-7262

2014-01-07 Thread Sebastiaan Couwenberg
On 01/08/2014 08:25 AM, Salvatore Bonaccorso wrote: > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. The new mapserver packages were prepared before the CVE was available. > Please adjust the affected versio

Bug#734565: mapserver: CVE-2013-7262

2014-01-07 Thread Salvatore Bonaccorso
Package: mapserver Severity: important Tags: security upstream patch Hi, the following vulnerability was published for mapserver. CVE-2013-7262[0]: | SQL injection vulnerability in the msPostGISLayerSetTimeFilter | function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time | service is