Out-of-bounds write in MapServer - #VU147312
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based out-of-bounds write in msInterpolationDataset() in src/interpolation.c when processing WMS GetMap requests with an output grid smaller than the sample count. A remote attacker can send a crafted WMS GetMap request with small WIDTH and HEIGHT values to cause a denial of service.
The vulnerable layer uses CONNECTIONTYPE IDW or CONNECTIONTYPE KERNELDENSITY.