Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pypam | Pypam | * | 0.5.0 (including) |
Python-pam | Ubuntu | devel | * |
Python-pam | Ubuntu | hardy | * |
Python-pam | Ubuntu | lucid | * |
Python-pam | Ubuntu | maverick | * |
Python-pam | Ubuntu | natty | * |
Python-pam | Ubuntu | oneiric | * |