HomeSgiCVE-2012-3418

CVE-2012-3418

UNKNOWN
5.0CVSS
Published: 2012-08-27
Updated: 2025-04-11
AI Analysis

Description

libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch function in p_fetch.c; (10) the namelen field in the __pmDecodeInstanceReq function in p_instance.c; (11) the buflen field to the __pmDecodeText function in p_text.c; (12) PDU_INSTANCE packets to the __pmDecodeInstance in p_instance.c; or the (13) c_numpmid or (14) v_numval fields to the __pmDecodeLogControl function in p_lcontrol.c, which triggers integer overflows, heap-based buffer overflows, and/or buffer over-reads.

CVSS Metrics

Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Access Vector
network
Access Cmplx
low
Auth
none
Confidentiality
none
Integrity
none
Availability
partial
Weaknesses
CWE-189

Metadata

Primary Vendor
SGI
Published
8/27/2012
Last Modified
4/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

sgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilotsgi : performance_co-pilot

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2012-3418 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com