CVE-2014-9984

CRITICAL

glibc < 2.19 - Buffer Overflow in nscd Netgroup Request Handling

Title source: llm
STIX 2.1

Description

nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.

References (9)

Core 9
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://sourceware.org/bugzilla/show_bug.cgi?id=16695
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99071
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Jun/18
Mailing List mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Jun/14
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Sep/7
Mailing List mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Sep/7

Scores

CVSS v3 9.8
EPSS 0.0050
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
gnu/glibc < 2.19
Published Jun 12, 2017
Tracked Since Feb 18, 2026