PT-2020-16951 · Maxmind+8 · Libmaxminddb+8

Seviezhou

·

Published

2020-08-04

·

Updated

2024-03-12

·

CVE-2020-28241

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libmaxminddb versions prior to 1.4.3
Description The issue is a heap-based buffer over-read in the dump entry data list function in maxminddb.c. This occurs in libmaxminddb before version 1.4.3.
Recommendations For versions prior to 1.4.3, update to version 1.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the dump entry data list function in maxminddb.c until a patch is available.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2024:0768
ALT-PU-2020-2831
ALT-PU-2023-6412
BIT-LIBMAXMINDDB-2020-28241
CESA-2024_0768
CVE-2020-28241
DLA-2445-1
MGASA-2020-0471
OESA-2021-1287
RHSA-2024:0750
RHSA-2024:0751
RHSA-2024:0768
RHSA-2024_0768
RLSA-2024:0768
USN-4631-1
USN-5751-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Ubuntu
Libmaxminddb