Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status
NVD contains:

Last updated: 7/22/2014 5:42:30 PM

CVE Publication rate: 18.53

Email List

NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index
Vulnerability Workload Index: 6.36
About Us
NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security's National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).

National Cyber Awareness System

Vulnerability Summary for CVE-2012-3418

Original release date: 08/27/2012
Last revised: 10/08/2013
Source: US-CERT/NIST

Overview

libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch function in p_fetch.c; (10) the namelen field in the __pmDecodeInstanceReq function in p_instance.c; (11) the buflen field to the __pmDecodeText function in p_text.c; (12) PDU_INSTANCE packets to the __pmDecodeInstance in p_instance.c; or the (13) c_numpmid or (14) v_numval fields to the __pmDecodeLogControl function in p_lcontrol.c, which triggers integer overflows, heap-based buffer overflows, and/or buffer over-reads.

Impact

CVSS Severity (version 2.0):
CVSS v2 Base Score: 5.0 (MEDIUM) (AV:N/AC:L/Au:N/C:N/I:N/A:P) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 10.0
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type: Allows disruption of service

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

External Source: FEDORA
Name: FEDORA-2012-12024
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commitdiff;h=bfb3ab8c6b3d75b1a6580feee76a7d0925a3633c
Type: Patch Information
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841284
External Source: DEBIAN
Name: DSA-2533
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841126
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commit;h=f190942b552aa80d59bbe718866aa00b8e3fd5cc
External Source: SUSE
Name: SUSE-SU-2013:0190
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=blob;f=CHANGELOG;h=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5;hb=fe51067ae869a4d59f350ac319b09edcb77ac8e6
External Source: FEDORA
Name: FEDORA-2012-12076
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commitdiff;h=49c679c44425915a8d6aa4af5f90b35384843c12
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841180
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841249
External Source: SUSE
Name: openSUSE-SU-2012:1081
External Source: SUSE
Name: openSUSE-SU-2012:1079
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841183
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=840920
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commit;h=babd6c5c527f87ec838c13a1b4eba612af6ea27c
Type: Patch Information
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=840822
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841240
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841698
External Source: SUSE
Name: openSUSE-SU-2012:1036
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commitdiff;h=cced6012b4b93bfb640a9678589ced5416743910
Type: Patch Information
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commit;h=e4faa1f0ba29151340920d975fc7639adf8371d5
Type: Patch Information
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commitdiff;h=9f4e392c97ce42744ec73f82268ce6c815fdca0e
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841112
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commitdiff;h=7eb479b91ef12bf89a15b078af2107c8c4746a4a
Type: Patch Information
External Source: MLIST
Name: [oss-security] 20120816 pcp: Multiple security flaws
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commit;h=b441980d53be1835b25f0cd6bcc0062da82032dd
Type: Patch Information
External Source: MISC
Name: https://bugzilla.redhat.com/show_bug.cgi?id=841159
External Source: CONFIRM
Name: http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git;a=commitdiff;h=f0eaefe046b1061797f45b0c20bb2ac371b504a5
Type: Patch Information

Technical Details

Vulnerability Type (View All)