PT-2022-5350 · Sudo+5 · Sudo+5

Hugo Lefeuvre

·

Published

2022-10-28

·

Updated

2025-05-07

·

CVE-2022-43995

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Sudo versions 1.8.0 through 1.9.12
Description The issue is related to an array-out-of-bounds error in the plugins/sudoers/auth/passwd.c file of the Sudo program when using the crypt() password backend. This error can result in a heap-based buffer over-read, potentially allowing an attacker to cause a denial of service. The impact can vary depending on system libraries, compiler, and processor architecture. The issue can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer.
Recommendations For Sudo versions 1.8.0 through 1.9.12, consider disabling the crypt() password backend as a temporary workaround until a patch is available. Restrict access to the plugins/sudoers/auth/passwd.c file to minimize the risk of exploitation. Avoid using passwords of seven characters or fewer in the affected Sudo versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3014
ALT-PU-2022-3305
ALT-PU-2023-1147
ALT-PU-2023-1657
AZL-11400
BDU:2022-06664
CVE-2022-43995
MGASA-2022-0426
OESA-2022-2079
OPENSUSE-SU-2022_4001-1
OPENSUSE-SU-2022_4077-1
OPENSUSE-SU-2024:12483-1
ROSA-SA-2023-2189
SUSE-SU-2022:3886-1
SUSE-SU-2022:3938-1
SUSE-SU-2022:4001-1
SUSE-SU-2022:4077-1
SUSE-SU-2022:4240-1
SUSE-SU-2022:4280-1
SUSE-SU-2022_3886-1
SUSE-SU-2022_3938-1
SUSE-SU-2022_4001-1
SUSE-SU-2022_4077-1
SUSE-SU-2022_4240-1
SUSE-SU-2022_4280-1

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Sudo
Suse