CVE-2020-28241

Name
CVE-2020-28241
Description
libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/maxmind/libmaxminddb/issues/236
Patch https://github.com/maxmind/libmaxminddb/pull/237
Patch https://github.com/maxmind/libmaxminddb/compare/1.4.2...1.4.3
Mailing List https://lists.debian.org/debian-lts-announce/2020/11/msg00019.html
Third Party Advisory https://security.gentoo.org/glsa/202011-15
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6WUK4UCOB5FJVK36E22IRLEYGKMUWGBG/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ELTOHZBPO6XVUVADP4DPZBNQCPTYOQBV/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:maxmind:libmaxminddb:*:*:*:*:*:*:*:* libmaxminddb >= None < 1.4.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libmaxminddb 3.12-main 1.4.3-r0 Timo Teräs <timo.teras@iki.fi> fixed
libmaxminddb 3.11-main 1.4.2-r2 Timo Teräs <timo.teras@iki.fi> fixed
libmaxminddb 3.10-main 1.3.2-r1 Timo Teräs <timo.teras@iki.fi> fixed