CVE-2024-33602
HIGHDescription
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Is your site exposed to CVE-2024-33602?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gnu | glibc |
| debian | debian_linux |
| netapp | h300s_firmware |
| netapp | h300s |
| netapp | h500s_firmware |
| netapp | h500s |
| netapp | h700s_firmware |
| netapp | h700s |
| netapp | h410s_firmware |
| netapp | h410s |
| netapp | h410c_firmware |
| netapp | h410c |
| netapp | element_software |
| netapp | solidfire_\&_hci_management_node |
| netapp | solidfire_\&_hci_storage_node |
| netapp | hci_bootstrap_os |
References
Other References
Frequently Asked Questions
What is CVE-2024-33602? +
How severe is CVE-2024-33602? +
What products are affected by CVE-2024-33602? +
How do I check if I'm vulnerable to CVE-2024-33602? +
Related Vulnerabilities
When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause …
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and …
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to …
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such …
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be …
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS …