libmaxminddb before 1.4.3 has a heap-based buffer over-read in
dump_entry_data_list in maxminddb.c (CVE-2020-28241).
- https://bugs.mageia.org/show_bug.cgi?id=27608
- https://lists.debian.org/debian-lts-announce/2020/11/msg00019.html
- https://ubuntu.com/security/notices/USN-4631-1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6WUK4UCOB5FJVK36E22IRLEYGKMUWGBG/
- https://www.cve.org/CVERecord?id=CVE-2020-28241
- 7/core/libmaxminddb-1.3.2-3.1.mga7
Get the latest Linux and open source security news straight to your inbox.