Back

LOW

sudo: does not flush stdin buffer on password timeout

Published Jul 7, 2008

Description

sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of sudo as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 7, 2008
Updated Aug 7, 2024
Reserved Jul 7, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jul 4, 2008