nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 5.9 | Medium | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Product | Vendor | Version |
---|---|---|
glibc | The GNU C Library | ArubaOS-Switch 16.01.xxxx: All versions. |