7.5
CVE-2012-1502
- EPSS 14.29%
- Veröffentlicht 16.06.2012 00:55:06
- Zuletzt bearbeitet 16.06.2026 23:39:38
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 14.29% | 0.961 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://lists.opensuse.org/opensuse-updates/2012-04/msg00027.html
http://secunia.com/advisories/48312
http://secunia.com/advisories/48332
http://secunia.com/advisories/48746
http://ubuntu.com/usn/usn-1395-1
http://www.debian.org/security/2012/dsa-2430
http://www.lsexperts.de/advisories/lse-2012-03-01.txt
http://www.osvdb.org/79892
https://exchange.xforce.ibmcloud.com/vulnerabilities/73857
https://security.gentoo.org/glsa/201507-09