Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28241

Опубликовано: 04 авг. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.

An improper initialization issue was found in libmaxminddb. A remote user could exploit this flaw by sending a specially crafted MaxMind DB file that, when parsed by an application linked to libmaxminddb, would possibly crash the application, resulting in a denial of service condition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libmaxminddbWill not fix
Red Hat Enterprise Linux 9libmaxminddbNot affected
Red Hat Enterprise Linux 8libmaxminddbFixedRHSA-2024:076812.02.2024
Red Hat Enterprise Linux 8.6 Extended Update SupportlibmaxminddbFixedRHSA-2024:075108.02.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportlibmaxminddbFixedRHSA-2024:075008.02.2024
RHEL-8 based Middleware Containersrh-sso-7/sso76-openshift-rhel8FixedRHSA-2024:168604.04.2024
RHEL-8 based Middleware Containersrh-sso-7/sso7-rhel8-operator-bundleFixedRHSA-2024:168604.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-665->CWE-170->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1895379libmaxminddb: improper initialization in dump_entry_data_list() in maxminddb.c

EPSS

Процентиль: 43%
0.00209
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 5 лет назад

libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.

CVSS3: 6.5
nvd
почти 5 лет назад

libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.

CVSS3: 6.5
debian
почти 5 лет назад

libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_en ...

rocky
больше 1 года назад

Moderate: libmaxminddb security update

github
около 3 лет назад

libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.

EPSS

Процентиль: 43%
0.00209
Низкий

6.5 Medium

CVSS3