CVE-2012-3420
published 2012-08-27CVE-2012-3420: Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.44%
82.4th percentile
Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in libpcp/src/pdu.c.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcp | < pcp 3.6.5 (bookworm) | pcp 3.6.5 (bookworm) |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| sgi | performance_co-pilot | <= 3.6.4 | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2fm8-cg34-48gj: Multiple memory leaks in Performance Co-Pilot (PCP) before 3
ghsa_unreviewed·2022-05-17
CVE-2012-3420 [MEDIUM] GHSA-2fm8-cg34-48gj: Multiple memory leaks in Performance Co-Pilot (PCP) before 3
Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in libpcp/src/pdu.c.
OSV
CVE-2012-3420: Multiple memory leaks in Performance Co-Pilot (PCP) before 3
osv·2012-08-27·CVSS 5.0
CVE-2012-3420 [MEDIUM] CVE-2012-3420: Multiple memory leaks in Performance Co-Pilot (PCP) before 3
Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in libpcp/src/pdu.c.
Debian
CVE-2012-3420: pcp - Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote at...
vendor_debian·2012·CVSS 5.0
CVE-2012-3420 [MEDIUM] CVE-2012-3420: pcp - Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote at...
Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in libpcp/src/pdu.c.
Scope: local
bookworm: resolved (fixed in 3.6.5)
bullseye: resolved (fixed in 3.6.5)
forky: resolved (fixed in 3.6.5)
sid: resolved (fixed in 3.6.5)
trixie: resolved (fixed in 3.6.5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
bugzilla·2012-08-16·CVSS 5.0
CVE-2012-3418 [MEDIUM] CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_
Bugzilla
CVE-2012-3420 pcp: two memory leaks can lead to pcmd crash or trigger OOM killer
bugzilla·2012-07-19·CVSS 5.0
CVE-2012-3420 [MEDIUM] CVE-2012-3420 pcp: two memory leaks can lead to pcmd crash or trigger OOM killer
CVE-2012-3420 pcp: two memory leaks can lead to pcmd crash or trigger OOM killer
Florian Weimer of the Red Hat Product Security Team discovered two memory leaks in libpcp that can be abused by an unauthenticated remote attacker to crash pmcd (the PCP (Performance Co-Pilot) performance metrics collector daemon) or to consume enough memory to trigger the OOM killer, which may have impact on other processes.
Discussion:
This CVE comprises of two flaws:
bug #841298 pmcd leaks memory in DoFetch error path
bug #841319 In-band signaling in __pmGetPDU causes pmcd memory leak
Both bugs have respective upstream patches which addresses them.
---
Created pcp tracking bugs for this issue
Affects: epel-all [bug 848629]
---
This issue was addressed in Fedora and EPEL via the following security
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=68fb968b4ee635bb301dc9ab64e633b0d66d27b4http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=a7dc844d3586ea79887655a97c4252a79751fdaehttp://www.debian.org/security/2012/dsa-2533http://www.openwall.com/lists/oss-security/2012/08/16/1https://bugzilla.redhat.com/show_bug.cgi?id=841298https://bugzilla.redhat.com/show_bug.cgi?id=841319https://bugzilla.redhat.com/show_bug.cgi?id=841704https://hermes.opensuse.org/messages/15471040https://hermes.opensuse.org/messages/15540133https://hermes.opensuse.org/messages/15540172http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=68fb968b4ee635bb301dc9ab64e633b0d66d27b4http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=a7dc844d3586ea79887655a97c4252a79751fdaehttp://www.debian.org/security/2012/dsa-2533http://www.openwall.com/lists/oss-security/2012/08/16/1https://bugzilla.redhat.com/show_bug.cgi?id=841298https://bugzilla.redhat.com/show_bug.cgi?id=841319https://bugzilla.redhat.com/show_bug.cgi?id=841704https://hermes.opensuse.org/messages/15471040https://hermes.opensuse.org/messages/15540133https://hermes.opensuse.org/messages/15540172
2012-08-27
Published