Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:0768 - Security Advisory
Issued:
2024-02-12
Updated:
2024-02-12

RHSA-2024:0768 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: libmaxminddb security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libmaxminddb is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libmaxminddb package contains the MaxMind DB library.

Security Fix(es):

  • libmaxminddb: improper initialization in dump_entry_data_list() in maxminddb.c (CVE-2020-28241)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 1895379 - CVE-2020-28241 libmaxminddb: improper initialization in dump_entry_data_list() in maxminddb.c

CVEs

  • CVE-2020-28241

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
libmaxminddb-1.2.0-10.el8_9.1.src.rpm SHA-256: 56d369a38a32f939e6f54d505bd53ab7a31c2a09b128f5b515c7610e5861dc89
x86_64
libmaxminddb-1.2.0-10.el8_9.1.i686.rpm SHA-256: 6838623c2ae4a52a6f9d22509fe4b55e8a1c45de8b5a3b13653c6caa2bcac69e
libmaxminddb-1.2.0-10.el8_9.1.x86_64.rpm SHA-256: 51226cadf8b8327fbe85dd1db433169af8ac54f1f3255d6fcfcb7448ae2aa3c9
libmaxminddb-debuginfo-1.2.0-10.el8_9.1.i686.rpm SHA-256: a8222332bc6aa60c896ba3fcf209725d28ab197c13ef30f10dc3af5418aea41b
libmaxminddb-debuginfo-1.2.0-10.el8_9.1.x86_64.rpm SHA-256: 6d0c24a412443652673dee8b747e148438f678ec4cf102f6f8276f58b2fa77fb
libmaxminddb-debugsource-1.2.0-10.el8_9.1.i686.rpm SHA-256: 4c224246aa2fb0148578e8e3d6edd8f82e758f6e06ff0e726d71e3e660c7e840
libmaxminddb-debugsource-1.2.0-10.el8_9.1.x86_64.rpm SHA-256: d2f9ffe8219c48ba070b3c89868331ed67278f8df4d779da84e26926ab495d25
libmaxminddb-devel-1.2.0-10.el8_9.1.i686.rpm SHA-256: 98ec7f0e8156b7bde05ec4d9ed74c37ae01c2bac9eb6886b9a2fde70f255b2f4
libmaxminddb-devel-1.2.0-10.el8_9.1.x86_64.rpm SHA-256: c6d5c66c3e18768ba72a55b12c31c41ac2e83e8bae6155515477a620d70e6d5b

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
libmaxminddb-1.2.0-10.el8_9.1.src.rpm SHA-256: 56d369a38a32f939e6f54d505bd53ab7a31c2a09b128f5b515c7610e5861dc89
s390x
libmaxminddb-1.2.0-10.el8_9.1.s390x.rpm SHA-256: b5e5353232fee3aa4b9b7aee78933a55868ba574ecb70939ff13ff6881d21471
libmaxminddb-debuginfo-1.2.0-10.el8_9.1.s390x.rpm SHA-256: de703daafe573a593d1a5f317cc79926469d1e88da102fdb462a3cf16e7f3f1e
libmaxminddb-debugsource-1.2.0-10.el8_9.1.s390x.rpm SHA-256: 9d87d0060e40a27b941a1b290b546a6c7ee2e77319998705239f7691c5d495ae
libmaxminddb-devel-1.2.0-10.el8_9.1.s390x.rpm SHA-256: 1f2ae0474914f27644fbe7e2f6f2e286ed88b89939362f6d402df1ab7704db67

Red Hat Enterprise Linux for Power, little endian 8

SRPM
libmaxminddb-1.2.0-10.el8_9.1.src.rpm SHA-256: 56d369a38a32f939e6f54d505bd53ab7a31c2a09b128f5b515c7610e5861dc89
ppc64le
libmaxminddb-1.2.0-10.el8_9.1.ppc64le.rpm SHA-256: 5b8d19003f8d2c002c53152a4324c03154114496664ce715a862ef01bcbda522
libmaxminddb-debuginfo-1.2.0-10.el8_9.1.ppc64le.rpm SHA-256: 19f2db3e966849bd37a1ba7decc3d5962a4159cd677edf0d885e8381701dd94b
libmaxminddb-debugsource-1.2.0-10.el8_9.1.ppc64le.rpm SHA-256: 3aca578ecbb6c83ddd9cf49172dd5bb7b3582b13902b7537d5185dbebd09afeb
libmaxminddb-devel-1.2.0-10.el8_9.1.ppc64le.rpm SHA-256: 88084d52bdd14983e291c1e40c9692929e402f6abd62d8aaf0930010e78ff99a

Red Hat Enterprise Linux for ARM 64 8

SRPM
libmaxminddb-1.2.0-10.el8_9.1.src.rpm SHA-256: 56d369a38a32f939e6f54d505bd53ab7a31c2a09b128f5b515c7610e5861dc89
aarch64
libmaxminddb-1.2.0-10.el8_9.1.aarch64.rpm SHA-256: d501c49f1d14e1134d5d58c0b058962ceefeb75dd0d877a7888c6d9bce4e38aa
libmaxminddb-debuginfo-1.2.0-10.el8_9.1.aarch64.rpm SHA-256: f35266d1dd9a5021d5cb4c08135ea3cd2c10b516594723a3b09c6acd0124aadd
libmaxminddb-debugsource-1.2.0-10.el8_9.1.aarch64.rpm SHA-256: 2d85561e106d390cf5314f567f5d201cd78937292fe96ae96b4fca4ea970c685
libmaxminddb-devel-1.2.0-10.el8_9.1.aarch64.rpm SHA-256: 3d8312fdb671516ba87112b8d311d89e20ee521ea1035fcc5cd0a8c40956d349

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility