CVE-2014-9984
9.8
CRITICAL
CVSS 3.1
EPSS 0.50%
Description
nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.
How to fix CVE-2014-9984
To remediate CVE-2014-9984, upgrade the affected package to a fixed version below.
- Debian/glibc—upgrade to 2.19-14 or later
Is CVE-2014-9984 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.19-14
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |