CVE-2012-3419
published 2012-08-27CVE-2012-3419: Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.77%
75.5th percentile
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcp | < pcp 3.6.5 (bookworm) | pcp 3.6.5 (bookworm) |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| sgi | performance_co-pilot | <= 3.6.4 | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-3419: pcp - Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, w...
vendor_debian·2012·CVSS 5.0
CVE-2012-3419 [MEDIUM] CVE-2012-3419: pcp - Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, w...
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.
Scope: local
bookworm: resolved (fixed in 3.6.5)
bullseye: resolved (fixed in 3.6.5)
forky: resolved (fixed in 3.6.5)
sid: resolved (fixed in 3.6.5)
trixie: resolved (fixed in 3.6.5)
GHSA
GHSA-3c2g-cf55-wr6p: Performance Co-Pilot (PCP) before 3
ghsa_unreviewed·2022-05-17
CVE-2012-3419 [MEDIUM] CWE-200 GHSA-3c2g-cf55-wr6p: Performance Co-Pilot (PCP) before 3
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.
OSV
CVE-2012-3419: Performance Co-Pilot (PCP) before 3
osv·2012-08-27·CVSS 5.0
CVE-2012-3419 [MEDIUM] CVE-2012-3419: Performance Co-Pilot (PCP) before 3
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
bugzilla·2012-08-16·CVSS 5.0
CVE-2012-3418 [MEDIUM] CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_
Bugzilla
CVE-2012-3419 pcp: privileged information diclosure flaw
bugzilla·2012-07-19·CVSS 5.0
CVE-2012-3419 [MEDIUM] CVE-2012-3419 pcp: privileged information diclosure flaw
CVE-2012-3419 pcp: privileged information diclosure flaw
Florian Weimer of the Red Hat Product Security Team discovered that pmcd (the PCP (Performance Co-Pilot) performance metrics collector daemon) exports part of the /proc file system, including privileged information that could be used to aid in bypassing ASLR, as well as full commandline information on running programs.
Discussion:
Upstream patches:
http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commit;h=c20319d064af66dc5902661a3f05dccb24d7d177
http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commit;h=279950ec0f5bb70967b2d5260ac7f075b8187ca1
http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commit;h=8ff4984fee93bab09ea5c68b7ee18d1ab715bea1
http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commit;h=372b1b0d34
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6http://www.debian.org/security/2012/dsa-2533http://www.openwall.com/lists/oss-security/2012/08/16/1https://bugzilla.redhat.com/show_bug.cgi?id=841702https://hermes.opensuse.org/messages/15471040https://hermes.opensuse.org/messages/15540133https://hermes.opensuse.org/messages/15540172http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6http://www.debian.org/security/2012/dsa-2533http://www.openwall.com/lists/oss-security/2012/08/16/1https://bugzilla.redhat.com/show_bug.cgi?id=841702https://hermes.opensuse.org/messages/15471040https://hermes.opensuse.org/messages/15540133https://hermes.opensuse.org/messages/15540172
2012-08-27
Published