CVE-2024-33602

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/05/2024
Last modified:
18/06/2025

Description

nscd: netgroup cache assumes NSS callback uses in-buffer strings<br /> <br /> The Name Service Cache Daemon&amp;#39;s (nscd) netgroup cache can corrupt memory<br /> when the NSS callback does not store all strings in the provided buffer.<br /> The flaw was introduced in glibc 2.15 when the cache was added to nscd.<br /> <br /> This vulnerability is only present in the nscd binary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* 2.15 (including) 2.40 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*