VulnerabilityModified
CVE-2012-1502
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
HIGH 7.5EPSS 14.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 14.29% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- pypam/pypam
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2012-04/msg00027.html
- http://secunia.com/advisories/48312Vendor Advisory
- http://secunia.com/advisories/48332Vendor Advisory
- http://secunia.com/advisories/48746Vendor Advisory
- http://ubuntu.com/usn/usn-1395-1
- http://www.debian.org/security/2012/dsa-2430
- http://www.lsexperts.de/advisories/lse-2012-03-01.txtExploit
- http://www.osvdb.org/79892
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73857
- https://security.gentoo.org/glsa/201507-09
- http://lists.opensuse.org/opensuse-updates/2012-04/msg00027.html
- http://secunia.com/advisories/48312Vendor Advisory
- http://secunia.com/advisories/48332Vendor Advisory
- http://secunia.com/advisories/48746Vendor Advisory
- http://ubuntu.com/usn/usn-1395-1
- http://www.debian.org/security/2012/dsa-2430
- http://www.lsexperts.de/advisories/lse-2012-03-01.txtExploit
- http://www.osvdb.org/79892
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73857
- https://security.gentoo.org/glsa/201507-09
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.