CVE-2012-1502

high
Published 2012-06-16 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-1502

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/48746

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/48332

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/48312

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.4.2-13
debian debianbullseyefixed0.4.2-13
debian debianforkyfixed0.4.2-13
debian debiansidfixed0.4.2-13
debian debiantrixiefixed0.4.2-13

Application impact

VendorProductVersionsFixed
pypampypam{"endIncluding":"0.5.0"}

References

CWEs

CWE-399

Verify integrity in audit chain (admin only). AS-IS.