CVE-2014-9984
Last modified
CVE-2014-9984 is a vulnerability of currently unknown severity. nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.. EPSS estimates a 4.44% chance of exploitation in the next 30 days.
Description
nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | <= 2.19 |
References
- https://sourceware.org/bugzilla/show_bug.cgi?id=16695Issue Tracking, Patch, Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=16695Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-9984?
How severe is CVE-2014-9984?
How do I fix CVE-2014-9984?
Are you affected by CVE-2014-9984?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
