Back

CVE-2006-0056

Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function. NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.

Published: Feb 13, 2006 Modified: Jun 16, 2026
CWE-119

CVSS Metrics

Affected Products (9)

Vendor Product Version
pam-mysql pam-mysql 0.1
pam-mysql pam-mysql 0.2
pam-mysql pam-mysql 0.3
pam-mysql pam-mysql 0.4
pam-mysql pam-mysql 0.4.7
pam-mysql pam-mysql 0.5
pam-mysql pam-mysql 0.6
pam-mysql pam-mysql 0.7_pre1
pam-mysql pam-mysql 0.7_pre2

GitHub Security Advisory GHSA-w6xf-p38w-6xgp

Double free vulnerability in the authentication and authentication token alteration code in PAM...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 6.32%

Top 7% most likely to be exploited

Threat Score 31.9 / 100

Data Sources

NVD EPSS GitHub