Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9984

Опубликовано: 12 июн. 2017
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.

Отчет

This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux 5 as they did not include support for netgroups. Red Hat Enterprise Linux 6 and 7 already include the fixed version of the package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5compat-glibcNot affected
Red Hat Enterprise Linux 5glibcNot affected
Red Hat Enterprise Linux 6compat-glibcNot affected
Red Hat Enterprise Linux 6glibcNot affected
Red Hat Enterprise Linux 7compat-glibcNot affected
Red Hat Enterprise Linux 7glibcNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=1463288glibc: nscd buffer manipulation vulnerability could lead to code execution or crash

EPSS

Процентиль: 71%
0.00678
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.

CVSS3: 9.8
nvd
больше 8 лет назад

nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.

CVSS3: 9.8
debian
больше 8 лет назад

nscd in the GNU C Library (aka glibc or libc6) before version 2.20 doe ...

CVSS3: 9.8
github
больше 3 лет назад

nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.

fstec
больше 8 лет назад

Уязвимость службы nscd библиотеки, обеспечивающей системные вызовы и основные функции glibc, позволяющая нарушителю вызвать отказ в обслуживании или внедрение кода

EPSS

Процентиль: 71%
0.00678
Низкий

9.8 Critical

CVSS3