CVE-2008-3067
Publication date 7 July 2008
Last updated 24 July 2024
Ubuntu priority
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.
Status
Package | Ubuntu Release | Status |
---|---|---|
sudo | ||
Notes
kees
could not reproduce on Dapper or Gutsy, which predated the patch. I think this is a stand-alone vs PAM issue, and Debian/Ubuntu uses PAM.
Patch details
Package | Patch details |
---|---|
sudo |