CVE-2012-3419: Infoleak
Florian Weimer of the Red Hat Product Security Team discovered that pmcd (the PCP (Performance Co-Pilot) performance metrics collector daemon) exports part of the /proc file system, including privileged information that could be used to aid in bypassing ASLR, as well as full commandline information on running programs.
Other sources
Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3419?
CVE-2012-3419 is considered to have a moderate severity due to the potential exposure of sensitive information.
How do I fix CVE-2012-3419?
To fix CVE-2012-3419, upgrade Performance Co-Pilot to version 3.6.5 or later.
Which versions of Performance Co-Pilot are affected by CVE-2012-3419?
CVE-2012-3419 affects versions of Performance Co-Pilot prior to 3.6.5, including versions 2.1.1 through 2.2.
What type of information can be exposed due to CVE-2012-3419?
CVE-2012-3419 allows attackers to obtain sensitive information such as process memory mappings and command line arguments.
Is there a known exploit for CVE-2012-3419?
While a specific exploit for CVE-2012-3419 has not been publicly disclosed, the vulnerability itself poses a risk of information disclosure.