MEDIUM · 5.9

CVE-2024-33600

nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null poi...

Vulnerability Description

nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
GnuGlibc>= 2.15, < 2.40
DebianDebian Linux10.0
NetappActive Iq Unified Manager-
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH410S Firmware-
NetappH410S-
NetappH410C Firmware-
NetappH410C-
NetappH610C Firmware-
NetappH610C-
NetappH610S Firmware-
NetappH610S-
NetappH615C Firmware-
NetappH615C-
NetappHci Bootstrap Os-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-33600?

CVE-2024-33600 is a vulnerability with a CVSS score of 5.9 (MEDIUM). nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null poi...

How severe is CVE-2024-33600?

CVE-2024-33600 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-33600?

Check the references section above for vendor advisories and patch information. Affected products include: Gnu Glibc, Debian Debian Linux, Netapp Active Iq Unified Manager, Netapp H300S Firmware, Netapp H300S.