libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch function in p_fetch.c; (10) the namelen field in the __pmDecodeInstanceReq function in p_instance.c; (11) the buflen field to the __pmDecodeText function in p_text.c; (12) PDU_INSTANCE packets to the __pmDecodeInstance in p_instance.c; or the (13) c_numpmid or (14) v_numval fields to the __pmDecodeLogControl function in p_lcontrol.c, which triggers integer overflows, heap-based buffer overflows, and/or buffer over-reads
Published Aug 27, 2012
5.0
MEDIUMCVSS 2.0
EPSS 5.71%
Description
libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the __pmDecodeNameList function in p_pmns.c; (3) the numids value to the __pmDecodeIDList function in p_pmns.c; (4) unspecified vectors to the __pmDecodeProfile function in p_profile.c; the (5) status number value or (6) string number value to the __pmDecodeNameList function in p_pmns.c; (7) certain input to the __pmDecodeResult function in p_result.c; (8) the name length field (namelen) to the DecodeNameReq function in p_pmns.c; (9) a crafted PDU_FETCH request to the __pmDecodeFetch function in p_fetch.c; (10) the namelen field in the __pmDecodeInstanceReq function in p_instance.c; (11) the buflen field to the __pmDecodeText function in p_text.c; (12) PDU_INSTANCE packets to the __pmDecodeInstance in p_instance.c; or the (13) c_numpmid or (14) v_numval fields to the __pmDecodeLogControl function in p_lcontrol.c, which triggers integer overflows, heap-based buffer overflows, and/or buffer over-reads.
Affected products
No data.
- ≤ 3.6.4
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.8
- 2.1.9
- 2.1.10
- 2.1.11
- 2.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.71% (0.05706) | 92.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.75% (0.05753) | 92.06th | v5 (v2026.06.15) |
| Mar 21, 2026 | 3.58% (0.03579) | 87.63th | v4 (v2025.03.14) |
| Feb 26, 2026 | 4.78% (0.04782) | 89.26th | v4 (v2025.03.14) |
| Jul 21, 2025 | 6.47% (0.06467) | 90.63th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.84% (0.04844) | 88.53th | v4 (v2025.03.14) |
| Mar 29, 2025 | 11.65% (0.11653) | 89.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.84% (0.04844) | 88.79th | v4 (v2025.03.14) |
| Feb 25, 2025 | 9.67% (0.09667) | 94.91th | v3 (v2023.03.01) |
| Nov 9, 2024 | 10.89% (0.10892) | 95.29th | v3 (v2023.03.01) |
| Jan 23, 2024 | 9.88% (0.09877) | 94.29th | v3 (v2023.03.01) |
| Nov 8, 2023 | 8.69% (0.08694) | 93.85th | v3 (v2023.03.01) |
| Mar 7, 2023 | 7.25% (0.07252) | 92.95th | v3 (v2023.03.01) |
| Mar 6, 2023 | 8.23% (0.08228) | 93.49th | v2 (v2022.01.01) |
| Apr 1, 2022 | 8.23% (0.08228) | 92.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 8.23% (0.08228) | 82.23th | v2 (v2022.01.01) |
References (30)
- http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085324.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2012-August/085333.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00024.html vendor-advisoryx_refsource_SUSE
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=blob%3Bf=CHANGELOG%3Bh=16c9cbb2f61d909487ea1c3171f4ab33e5648ac5%3Bhb=fe51067ae869a4d59f350ac319b09edcb77ac8e6 x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=b441980d53be1835b25f0cd6bcc0062da82032dd x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=babd6c5c527f87ec838c13a1b4eba612af6ea27c x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=e4faa1f0ba29151340920d975fc7639adf8371d5 x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commit%3Bh=f190942b552aa80d59bbe718866aa00b8e3fd5cc x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=49c679c44425915a8d6aa4af5f90b35384843c12 x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=7eb479b91ef12bf89a15b078af2107c8c4746a4a x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=9f4e392c97ce42744ec73f82268ce6c815fdca0e x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=bfb3ab8c6b3d75b1a6580feee76a7d0925a3633c x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=cced6012b4b93bfb640a9678589ced5416743910 x_refsource_CONFIRM
- http://oss.sgi.com/cgi-bin/gitweb.cgi?p=pcp/pcp.git%3Ba=commitdiff%3Bh=f0eaefe046b1061797f45b0c20bb2ac371b504a5 x_refsource_CONFIRM
- http://www.debian.org/security/2012/dsa-2533 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2012/08/16/1 mailing-listx_refsource_MLIST
- https://bugzilla.redhat.com/show_bug.cgi?id=840822 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=840920 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841112 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841126 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841159 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841180 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841183 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841240 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841249 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841284 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=841698 x_refsource_MISC
- https://hermes.opensuse.org/messages/15471040 vendor-advisoryx_refsource_SUSE
- https://hermes.opensuse.org/messages/15540133 vendor-advisoryx_refsource_SUSE
- https://hermes.opensuse.org/messages/15540172 vendor-advisoryx_refsource_SUSE
Change history (0)
No recorded changes yet.