Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 9: DLA-2445-1 Critical: Libmaxminddb Heap Over-Read Exploit

debian lts
Calendar Grey November 10, 2020
Dist Debian Esm H88
Ubuntu Security Notice USN-4423-1 pertains to a critical buffer overflow vulnerability detected in the libcurl library, impacting secure file transfers.
A heap-based buffer over-read has been found in libmaxminddb, an IP geolocation database library

Summary

We recommend that you upgrade your libmaxminddb packages.

For the detailed security status of libmaxminddb please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libmaxminddb

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: libmaxminddb
Version: 1.2.0-1+deb9u1
CVE ID: CVE-2020-28241
Debian Bug: 973878

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here