openSUSE-SU-2012:0487Vendor advisory
http://lists.opensuse.org/opensuse-updates/2012-04/msg00027.html CVE-2012-1502
PyPAM Python bindings for PAM - Double-Free Corruption
Record summary
CVE-2012-1502 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPyPAM Python bindings for PAM - Double-Free CorruptionExploitDB exploitby Markus VervierNot analyzed1 file
References
1148312Third-party advisory
http://secunia.com/advisories/48312 48332Third-party advisory
http://secunia.com/advisories/48332 48746Third-party advisory
http://secunia.com/advisories/48746 USN-1395-1Vendor advisory
http://ubuntu.com/usn/usn-1395-1 DSA-2430Vendor advisory
http://www.debian.org/security/2012/dsa-2430 lsexperts.de
http://www.lsexperts.de/advisories/lse-2012-03-01.txt 79892vdb entry
http://www.osvdb.org/79892 pypam-password-dos(73857)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/73857 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-1502 GLSA-201507-09Vendor advisory
https://security.gentoo.org/glsa/201507-09