CVE-2024-33599

Severity CVSS v4.0:
Pending analysis
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
06/05/2024
Last modified:
18/06/2025

Description

nscd: Stack-based buffer overflow in netgroup cache<br /> <br /> If the Name Service Cache Daemon&amp;#39;s (nscd) fixed size cache is exhausted<br /> by client requests then a subsequent client request for netgroup data<br /> may result in a stack-based buffer overflow. This flaw was introduced<br /> in glibc 2.15 when the cache was added to nscd.<br /> <br /> This vulnerability is only present in the nscd binary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* 2.15 (including) 2.40 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:*