CVE-2012-3418

EUVD-2012-3388
libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch function in p_fetch.c; (10) the namelen field in the __pmDecodeInstanceReq function in p_instance.c; (11) the buflen field to the __pmDecodeText function in p_text.c; (12) PDU_INSTANCE packets to the __pmDecodeInstance in p_instance.c; or the (13) c_numpmid or (14) v_numval fields to the __pmDecodeLogControl function in p_lcontrol.c, which triggers integer overflows, heap-based buffer overflows, and/or buffer over-reads.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
sgiperformance_co-pilot
𝑥
≤ 3.6.4
sgiperformance_co-pilot
2.1.1
sgiperformance_co-pilot
2.1.2
sgiperformance_co-pilot
2.1.3
sgiperformance_co-pilot
2.1.4
sgiperformance_co-pilot
2.1.5
sgiperformance_co-pilot
2.1.6
sgiperformance_co-pilot
2.1.7
sgiperformance_co-pilot
2.1.8
sgiperformance_co-pilot
2.1.9
sgiperformance_co-pilot
2.1.10
sgiperformance_co-pilot
2.1.11
sgiperformance_co-pilot
2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pcp
bookworm
6.0.3-1.1
fixed
bullseye
5.2.6-1
fixed
sid
6.3.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pcp
hardy
dne
lucid
ignored
natty
ignored
oneiric
ignored
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
dne
utopic
ignored
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
not-affected
zesty
not-affected
Common Weakness Enumeration
References