{
  "threat_severity" : "Moderate",
  "public_date" : "2024-09-17T00:00:00Z",
  "bugzilla" : {
    "description" : "pcp: pmcd heap corruption through metric pmstore operations",
    "id" : "2310452",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2310452"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-787",
  "details" : [ "A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.", "A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6837",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "pcp-0:5.3.7-22.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Advanced Update Support",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6840",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.2",
    "package" : "pcp-0:5.0.2-9.el8_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6842",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.4",
    "package" : "pcp-0:5.2.5-8.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Telecommunications Update Service",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6842",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.4",
    "package" : "pcp-0:5.2.5-8.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6842",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.4",
    "package" : "pcp-0:5.2.5-8.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6843",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "pcp-0:5.3.5-10.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6843",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.6",
    "package" : "pcp-0:5.3.5-10.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6843",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.6",
    "package" : "pcp-0:5.3.5-10.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Extended Update Support",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6844",
    "cpe" : "cpe:/a:redhat:rhel_eus:8.8",
    "package" : "pcp-0:5.3.7-19.el8_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6848",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "pcp-0:6.2.0-5.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2024-11-12T00:00:00Z",
    "advisory" : "RHSA-2024:9452",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "pcp-0:6.2.2-7.el9_5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6846",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.0",
    "package" : "pcp-0:5.3.5-10.el9_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Extended Update Support",
    "release_date" : "2024-09-19T00:00:00Z",
    "advisory" : "RHSA-2024:6847",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.2",
    "package" : "pcp-0:6.0.1-8.el9_2"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Not affected",
    "package_name" : "pcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "pcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "pcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-45769\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-45769" ],
  "name" : "CVE-2024-45769",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}