CVE-2012-3420 — Missing Release of Memory after Effective Lifetime in Performance Co-pilot
Severity
5.0MEDIUMNVD
EPSS
3.5%
top 12.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 27
Latest updateMay 17
Description
Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in libpcp/src/pdu.c.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages2 packages
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2012-3420: pcp - Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote at...↗2012