Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-43995
Description:Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler, and processor architecture.
Test IDs: 1.3.6.1.4.1.25623.1.1.13.2022.309.01   1.3.6.1.4.1.25623.1.1.4.2022.4077.1   1.3.6.1.4.1.25623.1.1.10.2022.0426   1.3.6.1.4.1.25623.1.1.4.2022.4240.1   1.3.6.1.4.1.25623.1.1.2.2023.1047   1.3.6.1.4.1.25623.1.1.2.2023.1516   1.3.6.1.4.1.25623.1.1.4.2022.4280.1   1.3.6.1.4.1.25623.1.1.4.2022.3938.1   1.3.6.1.4.1.25623.1.1.2.2023.1400   1.3.6.1.4.1.25623.1.1.2.2023.1113   1.3.6.1.4.1.25623.1.1.2.2023.1022   1.3.6.1.4.1.25623.1.1.2.2023.1372   1.3.6.1.4.1.25623.1.1.4.2022.4001.1   1.3.6.1.4.1.25623.1.1.4.2022.3886.1   1.3.6.1.4.1.25623.1.1.2.2023.1337   1.3.6.1.4.1.25623.1.1.2.2023.1723   1.3.6.1.4.1.25623.1.1.2.2023.1137  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-43995
https://security.gentoo.org/glsa/202211-08
https://bugzilla.redhat.com/show_bug.cgi?id=2139911
https://github.com/sudo-project/sudo/commit/bd209b9f16fcd1270c13db27ae3329c677d48050
https://news.ycombinator.com/item?id=33465707
https://www.sudo.ws/security/advisories/




© 1998-2025 E-Soft Inc. All rights reserved.