← Vulnerability feed

Vulnerability record · CVE-2012-5530 · published 29 November 2012

CVE-2012-5530: Sgi performance co-pilot permissions and access controls vulnerability

Sgi · Performance Co Pilot

The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.

2.1 CVSS 2.0 Low EPSS 0.37% · top 71.9% CWE-264 · Permissions and access controls
2.1CVSS 2.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.

AV:L/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-5530 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2001-0823Sgi performance co-pilot vulnerabilityThe pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in th…EPSS 0.98%6.7CVE-2023-6917Sgi performance co-pilot toctou race condition vulnerabilityA vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services …EPSS 0.20%5.0CVE-2012-3418Sgi performance co-pilot vulnerabilitylibpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a …EPSS 5.7%5.0CVE-2012-3419Sgi performance co-pilot information exposure vulnerabilityPerformance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pi…EPSS 1.8%5.0CVE-2012-3420Sgi performance co-pilot vulnerabilityMultiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon cr…EPSS 2.4%5.0CVE-2012-3421Sgi performance co-pilot vulnerabilityThe pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attack…EPSS 3.3%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2012-5530), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.