Opensuse Pcp vulnerabilities
11 known vulnerabilities affecting opensuse/pcp.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM7LOW1
Vulnerabilities
Page 1 of 1
CVE-2024-3019P3HIGHCVSS 8.8≥ 0, < 6.2.1-12024-03-28
CVE-2024-3019 [HIGH] CVE-2024-3019: A flaw was found in PCP
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP ve
osv
CVE-2019-3695P3HIGHCVSS 7.8fixed in 3.11.9-5.8.1fixed in 4.3.1-3.5.3+2 more2020-03-03
CVE-2019-3695 [HIGH] CWE-94 CVE-2019-3695: A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterpr
A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise Module for Open Build
nvd
CVE-2019-3696P3HIGHCVSS 7.3fixed in 3.11.9-5.8.1fixed in 4.3.1-3.5.3+2 more2020-03-03
CVE-2019-3696 [HIGH] CWE-22 CVE-2019-3696: A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp
A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development Tools 15-SP1, SUSE Linux Enterprise M
nvd
CVE-2012-3418P4MEDIUMCVSS 5.0≥ 0, < 3.6.52012-08-27
CVE-2012-3418 [MEDIUM] CVE-2012-3418: libpcp in Performance Co-Pilot (PCP) before 3
libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns
osv
CVE-2023-6917P4MEDIUMCVSS 6.7≥ 0, < 6.2.0-12024-02-28
CVE-2023-6917 [MEDIUM] CVE-2023-6917: A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services a
A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This dispar
osv
CVE-2024-45769P4MEDIUMCVSS 5.5≥ 0, < 6.3.1-12024-09-19
CVE-2024-45769 [MEDIUM] CVE-2024-45769: A vulnerability was found in Performance Co-Pilot (PCP)
A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
osv
CVE-2012-3421P4MEDIUMCVSS 5.0≥ 0, < 3.6.52012-08-27
CVE-2012-3421 [MEDIUM] CVE-2012-3421: The pduread function in pdu
The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw."
osv
CVE-2012-3419P4MEDIUMCVSS 5.0≥ 0, < 3.6.52012-08-27
CVE-2012-3419 [MEDIUM] CVE-2012-3419: Performance Co-Pilot (PCP) before 3
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.
osv
CVE-2024-45770P4MEDIUMCVSS 4.4≥ 0, < 6.3.1-12024-09-19
CVE-2024-45770 [MEDIUM] CVE-2024-45770: A vulnerability was found in Performance Co-Pilot (PCP)
A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.
osv
CVE-2012-3420P4MEDIUMCVSS 5.0≥ 0, < 3.6.52012-08-27
CVE-2012-3420 [MEDIUM] CVE-2012-3420: Multiple memory leaks in Performance Co-Pilot (PCP) before 3
Multiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon crash) via a large number of PDUs with (1) a crafted context number to the DoFetch function in pmcd/src/dofetch.c or (2) a negative type value to the __pmGetPDU function in libpcp/src/pdu.c.
osv
CVE-2012-5530P4LOWCVSS 2.1≥ 0, < 3.7.12012-11-29
CVE-2012-5530 [LOW] CVE-2012-5530: The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3
The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.
osv