CVE Vulnerabilities

CVE-2008-3067

Published: Jul 07, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.

Affected Software

NameVendorStart VersionEnd Version
OpensuseSuse10.3 (including)10.3 (including)
SudoUbuntufeisty*
SudoUbuntuupstream*

References