CVE-2012-3420Missing Release of Memory after Effective Lifetime in Performance Co-pilot

CWE-3997 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
3.5%
top 12.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateMay 17

Description

Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in libpcp/src/pdu.c.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianopensuse/pcp< 3.6.5+3

🔴Vulnerability Details

3
GHSA
GHSA-2fm8-cg34-48gj: Multiple memory leaks in Performance Co-Pilot (PCP) before 32022-05-17
OSV
CVE-2012-3420: Multiple memory leaks in Performance Co-Pilot (PCP) before 32012-08-27
CVEList
CVE-2012-3420: Multiple memory leaks in Performance Co-Pilot (PCP) before 32012-08-27

📋Vendor Advisories

1
Debian
CVE-2012-3420: pcp - Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote at...2012

💬Community

2
Bugzilla
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]2012-08-16
Bugzilla
CVE-2012-3420 pcp: two memory leaks can lead to pcmd crash or trigger OOM killer2012-07-19
CVE-2012-3420 — SGI Performance Co-pilot vulnerability | cvebase