Lucene search

K
nvd3ff69d7a-14f2-4f67-a097-88dee7810d18NVD:CVE-2024-33601
HistoryMay 06, 2024 - 8:15 p.m.

CVE-2024-33601

2024-05-0620:15:11
CWE-617
3ff69d7a-14f2-4f67-a097-88dee7810d18
web.nvd.nist.gov
1
cve-2024-33601
name service cache daemon
glibc
denial of service
memory allocation
vulnerability

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

nscd: netgroup cache may terminate daemon on memory allocation failure

The Name Service Cache Daemon’s (nscd) netgroup cache uses xmalloc or
xrealloc and these functions may terminate the process due to a memory
allocation failure resulting in a denial of service to the clients. The
flaw was introduced in glibc 2.15 when the cache was added to nscd.

This vulnerability is only present in the nscd binary.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

4.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%