CVE-2012-3418Performance Co-pilot vulnerability

CWE-1897 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
3.6%
top 12.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateMay 17

Description

libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianopensuse/pcp< 3.6.5+3

🔴Vulnerability Details

3
GHSA
GHSA-wh7h-j72f-r8p8: libpcp in Performance Co-Pilot (PCP) before 32022-05-17
OSV
CVE-2012-3418: libpcp in Performance Co-Pilot (PCP) before 32012-08-27
CVEList
CVE-2012-3418: libpcp in Performance Co-Pilot (PCP) before 32012-08-27

📋Vendor Advisories

1
Debian
CVE-2012-3418: pcp - libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cau...2012

💬Community

2
Bugzilla
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]2012-08-16
Bugzilla
CVE-2012-3418 pcp: multiple integer and heap-based buffer overflow flaws2012-07-19
CVE-2012-3418 — SGI Performance Co-pilot vulnerability | cvebase