nscd: netgroup cache assumes NSS callback uses in-buffer...
High severity
Unreviewed
Published
May 6, 2024
to the GitHub Advisory Database
•
Updated Jul 22, 2024
Description
Published by the National Vulnerability Database
May 6, 2024
Published to the GitHub Advisory Database
May 6, 2024
Last updated
Jul 22, 2024
nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory
when the NSS callback does not store all strings in the provided buffer.
The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
References