CVE-2024-33599

Source
https://cve.org/CVERecord?id=CVE-2024-33599
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-33599.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-33599
Downstream
AZL (2)
BELL (1)
CGA (2)
CLSA (8)
DEBIAN (1)
MGASA (1)
MINI (2)
OESA (5)
openSUSE (1)
RHSA (9)
RLSA (2)
SUSE (5)
UBUNTU (1)
Related
Published
2024-05-06T19:21:54Z
Modified
2026-08-28T11:46:19Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
nscd: Stack-based buffer overflow in netgroup cache
Details

nscd: Stack-based buffer overflow in netgroup cache

If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd.

This vulnerability is only present in the nscd binary.

Database specific
{
    "cna_assigner":  "glibc",
    "cwe_ids":  [
        "CWE-121"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/33xxx/CVE-2024-33599.json"
}
References

Affected packages

Git / github.com/bminor/glibc

Affected ranges

Type
GIT
Repo
https://github.com/bminor/glibc
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "2.15"
        },
        {
            "fixed":  "2.40"
        }
    ],
    "source":  "CPE_RANGE"
}
Type
GIT
Repo
https://sourceware.org/git/glibc.git
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "2.15"
        },
        {
            "fixed":  "2.40"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

Other
changelog-ends-here
glibc-2.*
glibc-2.15
glibc-2.16
glibc-2.16-ports-merge
glibc-2.16-tps
glibc-2.16.0
glibc-2.16.90
glibc-2.17
glibc-2.17.90
glibc-2.18
glibc-2.18.90
glibc-2.19
glibc-2.19.90
glibc-2.20
glibc-2.20.90
glibc-2.21
glibc-2.21.90
glibc-2.22
glibc-2.22.90
glibc-2.23
glibc-2.23.90
glibc-2.24
glibc-2.24.90
glibc-2.25
glibc-2.25.90
glibc-2.26
glibc-2.26.9000
glibc-2.27
glibc-2.27.9000
glibc-2.28
glibc-2.28.9000
glibc-2.29
glibc-2.29.9000
glibc-2.30
glibc-2.30.9000
glibc-2.31
glibc-2.31.9000
glibc-2.32
glibc-2.32.9000
glibc-2.33
glibc-2.33.9000
glibc-2.34
glibc-2.34.9000
glibc-2.35
glibc-2.35.9000
glibc-2.36
glibc-2.36.9000
glibc-2.37
glibc-2.37.9000
glibc-2.38
glibc-2.38.9000
glibc-2.39
glibc-2.39.9000

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-33599.json"