The pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attackers to cause a denial of service (pmcd hang) by sending individual bytes of a PDU separately, related to an "event-driven programming flaw."
{
"binaries": [
{
"binary_name": "libpcp-gui2",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-gui2-dev",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-import-perl",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-import1",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-import1-dev",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-logsummary-perl",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-mmv-perl",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-mmv1",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-mmv1-dev",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-pmda-perl",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-pmda3",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-pmda3-dev",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-trace2",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp-trace2-dev",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp3",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "libpcp3-dev",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "pcp",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "pcp-import-collectl2pcp",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "pcp-import-iostat2pcp",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "pcp-import-mrtg2pcp",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "pcp-import-sar2pcp",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "pcp-import-sheet2pcp",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "pcp-testsuite",
"binary_version": "3.8.12ubuntu1"
},
{
"binary_name": "python-pcp",
"binary_version": "3.8.12ubuntu1"
}
],
"availability": "No subscription required"
}