Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2020-28241
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2020-28241
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28241.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-28241
Aliases
BIT-libmaxminddb-2020-28241
Downstream
ALPINE-CVE-2020-28241
DEBIAN-CVE-2020-28241
DLA-2445-1
OESA-2021-1287
RHSA-2024:0750
RHSA-2024:0751
RHSA-2024:0768
UBUNTU-CVE-2020-28241
USN-4631-1
USN-5751-1
Related
ALSA-2024:0768
MGASA-2020-0471
RLSA-2024:0768
Published
2020-11-06T05:15:10Z
Modified
2025-10-21T05:51:25.719304Z
Severity
6.5 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
[none]
Details
libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump
entry
data_list in maxminddb.c.
References
https://github.com/maxmind/libmaxminddb/compare/1.4.2...1.4.3
https://github.com/maxmind/libmaxminddb/issues/236
https://github.com/maxmind/libmaxminddb/pull/237
https://lists.debian.org/debian-lts-announce/2020/11/msg00019.html
https://security.gentoo.org/glsa/202011-15
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WUK4UCOB5FJVK36E22IRLEYGKMUWGBG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ELTOHZBPO6XVUVADP4DPZBNQCPTYOQBV/
Affected packages
Git
/
github.com/maxmind/libmaxminddb
Affected ranges
Type
GIT
Repo
https://github.com/maxmind/libmaxminddb
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
07797e9dfb6771190f9fa41a33babe19425ef552
Affected versions
0.*
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
CVE-2020-28241 - OSV