libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libmaxminddb | Maxmind | * | 1.4.3 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | libmaxminddb-0:1.2.0-10.el8_9.1 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | libmaxminddb-0:1.2.0-10.el8_6.1 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | libmaxminddb-0:1.2.0-10.el8_8.1 | * |
RHEL-8 based Middleware Containers | RedHat | rh-sso-7/sso76-openshift-rhel8:7.6-42 | * |
RHEL-8 based Middleware Containers | RedHat | rh-sso-7/sso7-rhel8-operator-bundle:7.6.7-4 | * |
Libmaxminddb | Ubuntu | bionic | * |
Libmaxminddb | Ubuntu | devel | * |
Libmaxminddb | Ubuntu | esm-apps/bionic | * |
Libmaxminddb | Ubuntu | esm-apps/xenial | * |
Libmaxminddb | Ubuntu | esm-infra/focal | * |
Libmaxminddb | Ubuntu | focal | * |
Libmaxminddb | Ubuntu | groovy | * |
Libmaxminddb | Ubuntu | hirsute | * |
Libmaxminddb | Ubuntu | impish | * |
Libmaxminddb | Ubuntu | jammy | * |
Libmaxminddb | Ubuntu | kinetic | * |
Libmaxminddb | Ubuntu | lunar | * |
Libmaxminddb | Ubuntu | mantic | * |
Libmaxminddb | Ubuntu | noble | * |
Libmaxminddb | Ubuntu | oracular | * |
Libmaxminddb | Ubuntu | plucky | * |
Libmaxminddb | Ubuntu | trusty | * |
Libmaxminddb | Ubuntu | upstream | * |
Libmaxminddb | Ubuntu | xenial | * |