-------------------------------------------------------------------------Debian LTS Advisory DLA-2445-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Markus Koschany
November 10, 2020                             https://wiki.debian.org/LTS
-------------------------------------------------------------------------Package        : libmaxminddb
Version        : 1.2.0-1+deb9u1
CVE ID         : CVE-2020-28241
Debian Bug     : 973878

A heap-based buffer over-read has been found in libmaxminddb, an IP geolocation
database library. This could be exploited when the mmdblookup tool is used to
open a specially crafted database file.

For Debian 9 stretch, this problem has been fixed in version
1.2.0-1+deb9u1.

We recommend that you upgrade your libmaxminddb packages.

For the detailed security status of libmaxminddb please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libmaxminddb

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-2445-1: libmaxminddb security update

November 10, 2020
A heap-based buffer over-read has been found in libmaxminddb, an IP geolocation database library

Summary

We recommend that you upgrade your libmaxminddb packages.

For the detailed security status of libmaxminddb please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libmaxminddb

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
-------------------------------------------------------------------------Package : libmaxminddb
Version : 1.2.0-1+deb9u1
CVE ID : CVE-2020-28241
Debian Bug : 973878

Related News