Re: [mapserver-users] 7.6.3 released - includes important security fix

2021-06-03 Thread Jeff McKenna via mapserver-users
The associated CVE security ID for this is: CVE-2021-32062 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32062 -jeff -- Jeff McKenna GatewayGeo: Developers of MS4W, MapServer Consulting and Training co-founder of FOSS4G http://gatewaygeo.com/ On 2021-04-30 7:55 p.m., Steve Lime

Re: [mapserver-users] SUM: MapServer PostGIS: WMS Layers Without Features

2021-06-03 Thread Rahkonen Jukka (MML) via mapserver-users
Hi, All Mapserver admins do that error every now and then. There is a configuration option in the QGIS WMS Connection editor “Ignore GetMap/GetTile/GetLegendGraphic URI reported in capabilities” that helps to access many misconfigured WMS servers. If you check that box the same base URL that

[mapserver-users] SUM: MapServer PostGIS: WMS Layers Without Features

2021-06-03 Thread Nathan L via mapserver-users
Earlier, I asked why my MapServer PostGIS implementation was producing a WMS service without any layers in it. The original question in detail is at the bottom of this summary. The responses here and in other forums were quite helpful. It narrowed down the problem to about ten areas, which I

Re: [mapserver-users] CGI variable "map" fails to validate.

2021-06-03 Thread Steve Lime via mapserver-users
I should note that 7.6.3 (also 7.4.5, 7.2.3 and 7.0.8) should make defining a value for MS_MAP_PATTERN much simpler. We updated things to use two filters instead of one. The first, MS_MAP_BAD_PATTERN, checks for problematic character sequences in the map value, for example /./, /../ or // and

Re: [mapserver-users] CGI variable "map" fails to validate.

2021-06-03 Thread Jeff McKenna via mapserver-users
Hi David, MS4W also uses PCRE for its regex engine, so Windows users will soon be facing these same issues as you (I'll be making this as easy as possible for the new Windows users). So to answer your question: I believe most users aren't yet aware of what regex engine they use, and, also I

Re: [mapserver-users] CGI variable "map" fails to validate.

2021-06-03 Thread David Pavlíček via mapserver-users
Hi Steve, your pattern works like a charm... escaped hyphen was the issue. I tested the previous regex with regex101.com and it matches with no problems against most of the available variants except PCRE. Which regex engine is suitable for a test against MapServer? Thank you. st 2. 6. 2021 v