Bug 775013 - VUL-1: CVE-2012-3421: pcp: event-driven programming flaw blocks pmcd from responding to other legitimate requests
VUL-1: CVE-2012-3421: pcp: event-driven programming flaw blocks pmcd from res...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Raymund Will
Security Team bot
maint:released:sle11-sp2:50663 maint:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-08-08 10:57 UTC by Matthias Weckbecker
Modified: 2013-01-24 17:53 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthias Weckbecker 2012-08-08 10:57:30 UTC
There has recently been a DoS flaw reported in pcp that could be exploited by
unauthenticated remote attackers.

Note:
-----
This issue is embargoed until the 15th of August 2012. Please keep details
inside SUSE and don't use the open build service to prepare patched pkgs.
Comment 1 Matthias Weckbecker 2012-08-08 10:58:09 UTC
Original quote from the mail:

  "A denial of service flaw in pmcd (the PCP (Performance Co-Pilot) performance
   metrics collector daemon) due to incorrect event-driven programming.
   Because the pduread() function in libpcp performs a select locally, waiting
   for more client data, an unauthenticated remote attacker could send individual
   bytes one by one, avoiding the timeout, and blocking pmcd in order to prevent
   it from responding to other legitimate requests."
Comment 3 Swamp Workflow Management 2012-08-09 08:43:05 UTC
The SWAMPID for this issue is 48666.
This issue was rated as important.
Please submit fixed packages until 2012-08-16.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 6 Swamp Workflow Management 2012-08-24 14:09:22 UTC
openSUSE-SU-2012:1036-1: An update that fixes four vulnerabilities is now available.

Category: security (low)
Bug References: 775009,775010,775011,775013
CVE References: CVE-2012-3418,CVE-2012-3419,CVE-2012-3420,CVE-2012-3421
Sources used:
openSUSE 12.1 (src):    pcp-3.6.5-5.4.1
Comment 7 Swamp Workflow Management 2012-09-03 09:09:14 UTC
openSUSE-SU-2012:1079-1: An update that fixes four vulnerabilities is now available.

Category: security (low)
Bug References: 775009,775010,775011,775013
CVE References: CVE-2012-3418,CVE-2012-3419,CVE-2012-3420,CVE-2012-3421
Sources used:
openSUSE 12.2 (src):    pcp-3.6.5-9.9.1
Comment 8 Swamp Workflow Management 2012-09-03 09:10:38 UTC
openSUSE-SU-2012:1081-1: An update that fixes four vulnerabilities is now available.

Category: security (low)
Bug References: 775009,775010,775011,775013
CVE References: CVE-2012-3418,CVE-2012-3419,CVE-2012-3420,CVE-2012-3421
Sources used:
openSUSE 11.4 (src):    pcp-3.6.5-140.1
Comment 9 Bernhard Wiedemann 2012-09-07 13:00:51 UTC
This is an autogenerated message for OBS integration:
This bug (775013) was mentioned in
https://build.opensuse.org/request/show/133233 Evergreen:11.2 / pcp
Comment 10 Bernhard Wiedemann 2012-09-11 09:00:25 UTC
This is an autogenerated message for OBS integration:
This bug (775013) was mentioned in
https://build.opensuse.org/request/show/133595 Evergreen:11.2 / pcp
Comment 11 Raymund Will 2013-01-10 13:30:02 UTC
Remaining issues are tracked in bnc#775009.
Comment 12 Swamp Workflow Management 2013-01-23 15:20:53 UTC
Update released for: libpcp3, pcp, pcp-debuginfo, pcp-debugsource, pcp-devel, pcp-import-iostat2pcp, pcp-import-mrtg2pcp, pcp-import-sar2pcp, pcp-import-sheet2pcp, perl-PCP-LogImport, perl-PCP-LogSummary, perl-PCP-MMV, perl-PCP-PMDA, permissions, permissions-debuginfo
Products:
SLE-DEBUGINFO 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP2 (i386, x86_64)
SLE-SDK 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP2 (i386, x86_64)
Comment 13 Swamp Workflow Management 2013-01-23 15:55:35 UTC
Update released for: libpcp3, pcp, pcp-debuginfo, pcp-devel, pcp-import-iostat2pcp, pcp-import-mrtg2pcp, pcp-import-sar2pcp, pcp-import-sheet2pcp, perl-PCP-LogImport, perl-PCP-LogSummary, perl-PCP-MMV, perl-PCP-PMDA, permissions
Products:
SLE-DESKTOP 10-SP4 (i386, x86_64)
SLE-SDK 10-SP4 (i386, ia64, ppc, s390x, x86_64)
SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Comment 14 Swamp Workflow Management 2013-01-24 16:04:46 UTC
Update released for: libpcp3, pcp, pcp-debuginfo, pcp-devel, pcp-import-iostat2pcp, pcp-import-mrtg2pcp, pcp-import-sar2pcp, pcp-import-sheet2pcp, perl-PCP-LogImport, perl-PCP-LogSummary, perl-PCP-MMV, perl-PCP-PMDA, permissions
Products:
SLE-SERVER 10-SP3-TERADATA (x86_64)