CVE-2012-1502: Pypam

High severity, CVSS 7.5. EPSS: 14.3% chance of exploitation in the next 30 days.

Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.

Affected products

  • Pypam Pypam: up to and including 0.5.0

Published 2012-06-16. Last modified 2026-06-16.