LWN.net Logo

python-pam: code execution

Package(s):python-pam CVE #(s):CVE-2012-1502
Created:March 8, 2012 Updated:April 12, 2012
Description: From the Ubuntu advisory:

Markus Vervier discovered that PyPAM incorrectly handled passwords containing NULL bytes. An attacker could exploit this to cause applications using PyPAM to crash, or possibly execute arbitrary code.

Alerts:
Ubuntu USN-1395-1 2012-03-08
Debian DSA-2430-1 2012-03-10
openSUSE openSUSE-SU-2012:0487-1 2012-04-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds