Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4pv-q5f7-2h55

Опубликовано: 06 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

nscd: netgroup cache assumes NSS callback uses in-buffer strings

The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd.

This vulnerability is only present in the nscd binary.

nscd: netgroup cache assumes NSS callback uses in-buffer strings

The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd.

This vulnerability is only present in the nscd binary.

EPSS

Процентиль: 45%
0.00227
Низкий

8.6 High

CVSS3

Дефекты

CWE-466

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 1 года назад

nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

CVSS3: 4
redhat
больше 1 года назад

nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

CVSS3: 7.4
nvd
больше 1 года назад

nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

CVSS3: 7.4
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.4
debian
больше 1 года назад

nscd: netgroup cache assumes NSS callback uses in-buffer strings The ...

EPSS

Процентиль: 45%
0.00227
Низкий

8.6 High

CVSS3

Дефекты

CWE-466