CVE-2008-3067
Published: 7 July 2008
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.
Notes
Author | Note |
---|---|
kees | could not reproduce on Dapper or Gutsy, which predated the patch. I think this is a stand-alone vs PAM issue, and Debian/Ubuntu uses PAM. |
Priority
Status
Package | Release | Status |
---|---|---|
sudo Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
|
feisty |
Ignored
(end of life, was needed)
|
|
gutsy |
Not vulnerable
|
|
hardy |
Not vulnerable
|
|
intrepid |
Not vulnerable
|
|
upstream |
Released
(1.6.9p12-1)
|
|
Patches: upstream: http://www.sudo.ws/cgi-bin/cvsweb/sudo/tgetpass.c?r1=1.115&r2=1.121 |