sudo w SUSE openSUSE 10.3 nie czyści bufora stdin po upływie limitu czasu przy wpisywaniu hasła, co może umożliwić lokalnym użytkownikom uzyskanie hasła poprzez odczyt stdin z procesu nadrzędnego po wyjściu procesu potomnego sudo.
▸ Pokaż oryginał (EN)
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.
AV:L/AC:L/Au:N/C:P/I:N/A:NSUSE Opensuse
APPSuse10.3
Powiązane podatności
Code injection w openSUSE Open Build Service 2.1 (przed 11 marca 2011)
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LS...
SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfa...
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to r...
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)