The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw."
{ "ubuntu_priority": "medium", "binaries": [ { "binary_name": "libpcp-gui2", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-gui2-dev", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-import-perl", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-import1", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-import1-dev", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-logsummary-perl", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-mmv-perl", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-mmv1", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-mmv1-dev", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-pmda-perl", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-pmda3", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-pmda3-dev", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-trace2", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp-trace2-dev", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp3", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "libpcp3-dev", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "pcp", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "pcp-import-collectl2pcp", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "pcp-import-iostat2pcp", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "pcp-import-mrtg2pcp", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "pcp-import-sar2pcp", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "pcp-import-sheet2pcp", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "pcp-testsuite", "binary_version": "3.8.12ubuntu1" }, { "binary_name": "python-pcp", "binary_version": "3.8.12ubuntu1" } ], "availability": "No subscription required" }