CVE-2012-3421
published 2012-08-27CVE-2012-3421: The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.33%
87.2th percentile
The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw."
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcp | < pcp 3.6.5 (bookworm) | pcp 3.6.5 (bookworm) |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| opensuse | pcp | >= 0 < 3.6.5 | 3.6.5 |
| sgi | performance_co-pilot | <= 3.6.4 | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
| sgi | performance_co-pilot | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-3421: pcp - The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6...
vendor_debian·2012·CVSS 5.0
CVE-2012-3421 [MEDIUM] CVE-2012-3421: pcp - The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6...
The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw."
Scope: local
bookworm: resolved (fixed in 3.6.5)
bullseye: resolved (fixed in 3.6.5)
forky: resolved (fixed in 3.6.5)
sid: resolved (fixed in 3.6.5)
trixie: resolved (fixed in 3.6.5)
GHSA
GHSA-5m4g-m6fj-7r63: The pduread function in pdu
ghsa_unreviewed·2022-05-17
CVE-2012-3421 [MEDIUM] GHSA-5m4g-m6fj-7r63: The pduread function in pdu
The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw."
OSV
CVE-2012-3421: The pduread function in pdu
osv·2012-08-27·CVSS 5.0
CVE-2012-3421 [MEDIUM] CVE-2012-3421: The pduread function in pdu
The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
bugzilla·2012-08-16·CVSS 5.0
CVE-2012-3418 [MEDIUM] CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
CVE-2012-3418 CVE-2012-3419 CVE-2012-3420 CVE-2012-3421 pcp various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_
Bugzilla
CVE-2012-3421 pcp: event-driven programming flaw blocks pmcd from responding to other legitimate requests
bugzilla·2012-07-19·CVSS 5.0
CVE-2012-3421 [MEDIUM] CVE-2012-3421 pcp: event-driven programming flaw blocks pmcd from responding to other legitimate requests
CVE-2012-3421 pcp: event-driven programming flaw blocks pmcd from responding to other legitimate requests
Florian Weimer of the Red Hat Product Security Team discovered a denial of service flaw in pmcd (the PCP (Performance Co-Pilot) performance metrics collector daemon) due to incorrect event-driven programming. Because the pduread() function in libpcp performs a select locally, waiting for more client data, an unauthenticated remote attacker could send individual bytes one by one, avoiding the timeout, and blocking pmcd in order to prevent it from responding to other legitimate requests.
Discussion:
Created attachment 602308
Resolve an event-driven programming flaw in pmcd
This is Ken's patch to address this bug. Have had it in my quilt series for awhile, seems to be causing fewer re
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=9ba85dca940de976176ce196fd5e3c4170936354http://www.debian.org/security/2012/dsa-2533http://www.openwall.com/lists/oss-security/2012/08/16/1https://bugzilla.redhat.com/show_bug.cgi?id=841706https://hermes.opensuse.org/messages/15471040https://hermes.opensuse.org/messages/15540133https://hermes.opensuse.org/messages/15540172http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.htmlhttp://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=9ba85dca940de976176ce196fd5e3c4170936354http://www.debian.org/security/2012/dsa-2533http://www.openwall.com/lists/oss-security/2012/08/16/1https://bugzilla.redhat.com/show_bug.cgi?id=841706https://hermes.opensuse.org/messages/15471040https://hermes.opensuse.org/messages/15540133https://hermes.opensuse.org/messages/15540172
2012-08-27
Published