LOW
sudo: does not flush stdin buffer on password timeout
Published Jul 7, 2008
2.1
LOWCVSS 2.0
EPSS 0.30%
Description
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.
Affected products
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of sudo as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Weaknesses (1)
References (6)
- http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2008-3067 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=454398 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43618 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-3067
- https://www.cve.org/CVERecord?id=CVE-2008-3067
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html | vendor-advisoryx_refsource_SUSE | |
| https://access.redhat.com/security/cve/CVE-2008-3067 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=454398 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/43618 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2008-3067 | ||
| https://www.cve.org/CVERecord?id=CVE-2008-3067 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 7, 2008
Updated Aug 7, 2024
Reserved Jul 7, 2008
Link CVE-2008-3067
CISA Vulnrichment
Updated n/a