Vulnerability Description
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pypam | Pypam | <= 0.5.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-updates/2012-04/msg00027.html
- http://secunia.com/advisories/48312Vendor Advisory
- http://secunia.com/advisories/48332Vendor Advisory
- http://secunia.com/advisories/48746Vendor Advisory
- http://ubuntu.com/usn/usn-1395-1
- http://www.debian.org/security/2012/dsa-2430
- http://www.lsexperts.de/advisories/lse-2012-03-01.txtExploit
- http://www.osvdb.org/79892
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73857
- https://security.gentoo.org/glsa/201507-09
- http://lists.opensuse.org/opensuse-updates/2012-04/msg00027.html
- http://secunia.com/advisories/48312Vendor Advisory
- http://secunia.com/advisories/48332Vendor Advisory
- http://secunia.com/advisories/48746Vendor Advisory
- http://ubuntu.com/usn/usn-1395-1
FAQ
What is CVE-2012-1502?
CVE-2012-1502 is a vulnerability with a CVSS score of 7.5 (HIGH). Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ...
How severe is CVE-2012-1502?
CVE-2012-1502 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-1502?
Check the references section above for vendor advisories and patch information. Affected products include: Pypam Pypam.