CVE-2024-33602

Published May 6, 2024

Last updated 4 months ago

Overview

Description
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Source
3ff69d7a-14f2-4f67-a097-88dee7810d18
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.6
Impact score
4.7
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Severity
HIGH

Weaknesses

3ff69d7a-14f2-4f67-a097-88dee7810d18
CWE-466

Social media

Hype score
Not currently trending