CVE-2012-1502
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 14%
from disclosure to weapon0 days
Published on NVDJun 16
1st PoCMar 10
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/18579unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-updates/2012-04/msg00027.htmlhttp://secunia.com/advisories/48312http://secunia.com/advisories/48332http://secunia.com/advisories/48746https://exchange.xforce.ibmcloud.com/vulnerabilities/73857https://security.gentoo.org/glsa/201507-09http://ubuntu.com/usn/usn-1395-1http://www.debian.org/security/2012/dsa-2430http://www.lsexperts.de/advisories/lse-2012-03-01.txthttp://www.osvdb.org/79892