Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-33601

Опубликовано: 24 апр. 2024
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

A flaw was found in the glibc netgroup cache. The netgroup cache uses xmalloc/xrealloc and may terminate the process due to a memory allocation failure.

Отчет

The flaw in the glibc netgroup cache, while concerning, is categorized as a low severity issue due to several factors. Firstly, the exploitation of this vulnerability requires specific conditions, such as a memory allocation failure within the netgroup cache, which may not occur frequently in typical usage scenarios. Additionally, the impact of such failures is limited to the termination of the affected process, rather than facilitating unauthorized access or data manipulation. Furthermore, the likelihood of successful exploitation and the potential for widespread harm are comparatively low, given the specific nature of the vulnerability and its constrained impact. This issue affects the nscd RPM package and not the glibc RPM package itself. Affected components are tracked by their RPM source package, in this case, the nscd binary package is built from the glibc source package, hence the affected component is glibc.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10glibcNot affected
Red Hat Enterprise Linux 6compat-glibcNot affected
Red Hat Enterprise Linux 6glibcOut of support scope
Red Hat Enterprise Linux 7compat-glibcNot affected
Red Hat Enterprise Linux 7glibcFixedRHSA-2024:358804.06.2024
Red Hat Enterprise Linux 8glibcFixedRHSA-2024:334423.05.2024
Red Hat Enterprise Linux 8glibcFixedRHSA-2024:334423.05.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportglibcFixedRHSA-2024:346429.05.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportglibcFixedRHSA-2024:330923.05.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceglibcFixedRHSA-2024:330923.05.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-703
https://bugzilla.redhat.com/show_bug.cgi?id=2277205glibc: netgroup cache may terminate daemon on memory allocation failure

EPSS

Процентиль: 16%
0.00051
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 1 года назад

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

CVSS3: 7.3
nvd
около 1 года назад

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

CVSS3: 7.3
msrc
около 1 года назад

Описание отсутствует

CVSS3: 7.3
debian
около 1 года назад

nscd: netgroup cache may terminate daemon on memory allocation failure ...

CVSS3: 7.5
github
около 1 года назад

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

EPSS

Процентиль: 16%
0.00051
Низкий

4 Medium

CVSS3