CVE-2012-1502
python-pam - double free
EPSS 14.3%
Description
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
How to fix CVE-2012-1502
To remediate CVE-2012-1502, upgrade the affected package to a fixed version below.
- Debian/python-pam—upgrade to 0.4.2-13 or later
- Debian/python-pam—upgrade to 0.4.2-12.2+squeeze1 or later
Is CVE-2012-1502 being exploited?
Moderate — EPSS is 14.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.4.2-13
- from 0, < 0.4.2-12.2+squeeze1