{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2026-01-24T12:25:07Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/document/package-nativesdk-nscd","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/nativesdk-glibc/package-nativesdk-nscd/nativesdk-glibc/UNIHASH/document/package-nativesdk-nscd","https://rdf.openembedded.org/spdx/3.0/link-name":"a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3"}],"name":"package-nativesdk-nscd","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd","creationInfo":"_:CreationInfo1","description":"nscd, name service cache daemon, caches name service lookups for the passwd, group and hosts information.  It can damatically improvide performance with remote, such as NIS or NIS+, name services.","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/package/nativesdk-nscd"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:glibc:2.42:*:*:*:*:*:*:*"}],"name":"nativesdk-nscd","summary":"Name service cache daemon","software_primaryPurpose":"install","software_homePage":"http://www.gnu.org/software/libc/libc.html","software_packageVersion":"2.42+git"},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd/file/1","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/package/nativesdk-nscd/file/1"}],"name":"usr/local/oe-sdk-hardcoded-buildpath/sysroots/x86_64-tdxsdk-linux/etc/nscd.conf","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"63740e9a0662c400a70449ae87922058a2b5f22a1172ad85c3e1460f7404eb5d"}]},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd/file/2","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/package/nativesdk-nscd/file/2"}],"name":"usr/local/oe-sdk-hardcoded-buildpath/sysroots/x86_64-tdxsdk-linux/etc/init.d/nscd","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"5e9973d1fb86ecf2ab142fab13063b5be9e5aa537dbba94f0a8aeb0e52d3842c"}]},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd/file/3","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/package/nativesdk-nscd/file/3"}],"name":"usr/local/oe-sdk-hardcoded-buildpath/sysroots/x86_64-tdxsdk-linux/usr/bin/nscd","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"4893999ad416d9ecd930ea11582b25478a69baf366249d8f74b340bb3b85e064"}]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/relationship/02901b2e91ff4dda971987ac84fee6c9","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/relationship/02901b2e91ff4dda971987ac84fee6c9"}],"from":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd","relationshipType":"contains","to":["http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd/file/1","http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd/file/2","http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd/file/3"]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/relationship/9f5b54805a74762951f824692f6fa5f9","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/relationship/9f5b54805a74762951f824692f6fa5f9"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd"],"scope":"build"},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/relationship/a29dd09fdc211bc8de3e1d966dc5801f","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/relationship/a29dd09fdc211bc8de3e1d966dc5801f"}],"from":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/license/3_27_0/GPL-2_0-only_AND_LGPL-2_1-or-later"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/relationship/d05f21edf62131bf53eea7f38dfcdfa6","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/relationship/d05f21edf62131bf53eea7f38dfcdfa6"}],"from":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/vulnerability/CVE-2019-1010022","http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/vulnerability/CVE-2019-1010023","http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/vulnerability/CVE-2019-1010024","http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/vulnerability/CVE-2019-1010025"]},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/vex-not-affected/46389ec9b74c389a3d2e339420db59ae","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/vex-not-affected/46389ec9b74c389a3d2e339420db59ae"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/vulnerability/CVE-2019-1010024","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd"],"security_vexVersion":"1.0.0","security_impactStatement":"Upstream glibc maintainers dispute there is any issue and have no plans to address it further. this is being treated as a non-security bug and no real threat."},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/vex-not-affected/86827cbb22b4b8732039e2abe0a66ddd","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/vex-not-affected/86827cbb22b4b8732039e2abe0a66ddd"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/vulnerability/CVE-2019-1010025","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd"],"security_vexVersion":"1.0.0","security_impactStatement":"Allows for ASLR bypass so can bypass some hardening, not an exploit in itself, may allow easier access for another. 'ASLR bypass itself is not a vulnerability.'"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/vex-not-affected/df856dd2ed8306f3709bcb7ba22069c8","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/vex-not-affected/df856dd2ed8306f3709bcb7ba22069c8"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/vulnerability/CVE-2019-1010023","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd"],"security_vexVersion":"1.0.0","security_impactStatement":"Upstream glibc maintainers dispute there is any issue and have no plans to address it further. this is being treated as a non-security bug and no real threat."},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/vex-not-affected/ea7616fd5f7081395c5f7cc1937596af","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/a5ef31314aafd07fe90cec61cebca16524edf14239ad4944331bd0d77239f3c3/nativesdk-glibc/UNIHASH/vex-not-affected/ea7616fd5f7081395c5f7cc1937596af"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/ec95d1050dd09a8f8a75494b81742fe37717b475d9c126ce57fe8557b98d5881/nativesdk-glibc/UNIHASH/vulnerability/CVE-2019-1010022","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/nativesdk-glibc-9bf7b422-c754-5e1d-82e7-efca968fdfb9/5895f2815f5370960dfdcdfb4fd6e02033c9f8114a4bf93fc8e63f0bc1c2f893/package/nativesdk-nscd"],"security_vexVersion":"1.0.0","security_impactStatement":"Upstream glibc maintainers dispute there is any issue and have no plans to address it further. this is being treated as a non-security bug and no real threat."}]}