libmaxminddb: Denial of service — GLSA 202011-15

A vulnerability in libmaxminddb could lead to a Denial of Service condition.

Affected packages

dev-libs/libmaxminddb on all architectures
Affected versions < 1.4.3
Unaffected versions >= 1.4.3

Background

The libmaxminddb library provides a C library for reading MaxMind DB files, including the GeoIP2 databases from MaxMind.

Description

libmaxminddb used uninitialised memory when reading from a corrupt database file.

Impact

A remote attacker could entice a user to use a specially crafted database with libmaxminddb, possibly resulting in a Denial of Service condition.

Workaround

There is no known workaround at this time.

Resolution

All libmaxminddb users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-libs/libmaxminddb-1.4.3"
 

References

Release date
November 14, 2020

Latest revision
November 14, 2020: 1

Severity
normal

Exploitable
remote

Bugzilla entries