PT-2012-6329 · Pcp+1 · Performance Co-Pilot+1

Florian Weimer

+1

·

Published

1970-01-01

·

Updated

2013-02-07

·

CVE-2012-3420

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Performance Co-Pilot (PCP) versions prior to 3.6.5
Description The issue involves multiple memory leaks that can be exploited by remote attackers to cause a denial of service, either by consuming excessive memory or crashing the daemon. This can be achieved by sending a large number of PDUs with a crafted context number to the DoFetch function in pmcd/src/dofetch.c or a negative type value to the pmGetPDU function in libpcp/src/pdu.c. The vulnerability can be exploited remotely, potentially leading to a disruption in the availability of protected information.
Recommendations For Performance Co-Pilot (PCP) versions prior to 3.6.5, update to version 3.6.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the DoFetch function and the pmGetPDU function to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03711
BDU:2015-04394
BDU:2015-04395
BDU:2015-04396
BDU:2015-04397
BDU:2015-04398
BDU:2015-04399
BDU:2015-04400
BDU:2015-04401
CVE-2012-3420
DSA-2533-1
OPENSUSE-SU-2024:10165-1

Affected Products

Performance Co-Pilot
Suse