Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39008
HistoryJan 25, 2023 - 8:13 p.m.

Heap-Based Buffer Over-Read

2023-01-2520:13:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
sudo
vulnerability
crypt()
password
backend
heap-based buffer over-read
array-out-of-bounds error
local users
sudo

0.0004 Low

EPSS

Percentile

5.1%

sudo is vulnerable to Heap-Based Buffer Over-Read. The vulnerability exists in crypt() password backend, which contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that may result in a heap-based buffer over-read, that can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer.