CVE-2012-1502
Publication date 8 March 2012
Last updated 24 July 2024
Ubuntu priority
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-pam | 11.10 oneiric |
Fixed 0.4.2-12.2ubuntu2.11.10.1
|
11.04 natty |
Fixed 0.4.2-12.2ubuntu2.11.04.1
|
|
10.10 maverick |
Fixed 0.4.2-12.1ubuntu1.10.10.1
|
|
10.04 LTS lucid |
Fixed 0.4.2-12.1ubuntu1.10.04.1
|
|
8.04 LTS hardy | Ignored end of life |
References
Related Ubuntu Security Notices (USN)
- USN-1395-1
- PyPAM vulnerability
- 8 March 2012