CVE-2012-3418
published 2012-08-27CVE-2012-3418: libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with…
PriorityP432medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.75%
92.2th percentile
libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch function in p_fetch.c; (10) the namelen field in the __pmDecodeInstanceReq function in p_instance.c; (11) the buflen field to the __pmDecodeText function in p_text.c; (12) PDU_INSTANCE packets to the __pmDecodeInstance in p_instance.c; or the (13) c_numpmid or (14) v_numval fields to the __pmDecodeLogControl function in p_lcontrol.c, which triggers integer overflows, heap-based buffer overflows, and/or buffer over-reads.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcp | < pcp 3.6.5 (bookworm) | pcp 3.6.5 (bookworm) |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| sgi | performance_co-pilot | <= 3.6.4 | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wh7h-j72f-r8p8: libpcp in Performance Co-Pilot (PCP) before 3
ghsa_unreviewed·2022-05-17
CVE-2012-3418 [MEDIUM] GHSA-wh7h-j72f-r8p8: libpcp in Performance Co-Pilot (PCP) before 3
libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch fun
OSV
CVE-2012-3418: libpcp in Performance Co-Pilot (PCP) before 3
osv·2012-08-27·CVSS 5.0
CVE-2012-3418 [MEDIUM] CVE-2012-3418: libpcp in Performance Co-Pilot (PCP) before 3
libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch fun
Debian
CVE-2012-3418: pcp - libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cau...
vendor_debian·2012·CVSS 5.0
CVE-2012-3418 [MEDIUM] CVE-2012-3418: pcp - libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cau...
libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch fun
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
bugzilla·2012-08-16·CVSS 5.0
CVE-2012-3418 [MEDIUM] CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_
Bugzilla
CVE-2012-3418 pcp: multiple integer and heap-based buffer overflow flaws
bugzilla·2012-07-19·CVSS 5.0
CVE-2012-3418 [MEDIUM] CVE-2012-3418 pcp: multiple integer and heap-based buffer overflow flaws
CVE-2012-3418 pcp: multiple integer and heap-based buffer overflow flaws
Florian Weimer of the Red Hat Product Security Team discovered multiple integer and heap-based buffer overflow flaws in PCP (Performance Co-Pilot) libpcp protocol decoding functions. These flaws could lead to daemon crashes or the execution of arbitrary code with root privileges. Many of these flaws can be exploited without requiring the attacker to be authenticated.
Discussion:
The individual bugs that make up these flaws:
bug #840822 Crash in __pmDecodeCreds decoding crafted PDUs
bug #840920 pmcd heap-based buffer overflow in __pmDecodeNameList
bug #841112 __pmDecodeIDList lacks check against PDU size
bug #841126 Missing PDU length checks in __pmDecodeProfile
bug #841159 __pmDecodeResult multiple vulnerabilities
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=b441980d53be1835b25f0cd6bcc0062da82032ddhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=babd6c5c527f87ec838c13a1b4eba612af6ea27chttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=e4faa1f0ba29151340920d975fc7639adf8371d5http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=f190942b552aa80d59bbe718866aa00b8e3fd5cchttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=49c679c44425915a8d6aa4af5f90b35384843c12http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=7eb479b91ef12bf89a15b078af2107c8c4746a4ahttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=9f4e392c97ce42744ec73f82268ce6c815fdca0ehttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=bfb3ab8c6b3d75b1a6580feee76a7d0925a3633chttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=cced6012b4b93bfb640a9678589ced5416743910http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=f0eaefe046b1061797f45b0c20bb2ac371b504a5http://www.debian.org/security/2012/dsa-2533http://www.openwall.com/lists/oss-security/2012/08/16/1https://bugzilla.redhat.com/show_bug.cgi?id=840822https://bugzilla.redhat.com/show_bug.cgi?id=840920https://bugzilla.redhat.com/show_bug.cgi?id=841112https://bugzilla.redhat.com/show_bug.cgi?id=841126https://bugzilla.redhat.com/show_bug.cgi?id=841159https://bugzilla.redhat.com/show_bug.cgi?id=841180https://bugzilla.redhat.com/show_bug.cgi?id=841183https://bugzilla.redhat.com/show_bug.cgi?id=841240https://bugzilla.redhat.com/show_bug.cgi?id=841249https://bugzilla.redhat.com/show_bug.cgi?id=841284https://bugzilla.redhat.com/show_bug.cgi?id=841698https://hermes.opensuse.org/messages/15471040https://hermes.opensuse.org/messages/15540133https://hermes.opensuse.org/messages/15540172http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=b441980d53be1835b25f0cd6bcc0062da82032ddhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=babd6c5c527f87ec838c13a1b4eba612af6ea27chttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=e4faa1f0ba29151340920d975fc7639adf8371d5http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=f190942b552aa80d59bbe718866aa00b8e3fd5cchttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=49c679c44425915a8d6aa4af5f90b35384843c12http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=7eb479b91ef12bf89a15b078af2107c8c4746a4ahttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=9f4e392c97ce42744ec73f82268ce6c815fdca0ehttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=bfb3ab8c6b3d75b1a6580feee76a7d0925a3633chttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=cced6012b4b93bfb640a9678589ced5416743910http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=f0eaefe046b1061797f45b0c20bb2ac371b504a5http://www.debian.org/security/2012/dsa-2533http://www.openwall.com/lists/oss-security/2012/08/16/1https://bugzilla.redhat.com/show_bug.cgi?id=840822https://bugzilla.redhat.com/show_bug.cgi?id=840920https://bugzilla.redhat.com/show_bug.cgi?id=841112https://bugzilla.redhat.com/show_bug.cgi?id=841126https://bugzilla.redhat.com/show_bug.cgi?id=841159https://bugzilla.redhat.com/show_bug.cgi?id=841180https://bugzilla.redhat.com/show_bug.cgi?id=841183https://bugzilla.redhat.com/show_bug.cgi?id=841240https://bugzilla.redhat.com/show_bug.cgi?id=841249https://bugzilla.redhat.com/show_bug.cgi?id=841284https://bugzilla.redhat.com/show_bug.cgi?id=841698https://hermes.opensuse.org/messages/15471040https://hermes.opensuse.org/messages/15540133https://hermes.opensuse.org/messages/15540172
2012-08-27
Published