Sploitus

CVE-2022-43995

No indexed exploits for CVE-2022-43995 yet

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler, and processor architecture.

Affected products
Alt Linux, Astra Linux, Debian, Red Os, Sudo, Suse
Sudo Project Sudo
< 1.9.12
CVSS 3.1
7.1 HIGH
EPSS
0.3% (19th percentile)
Weakness
CWE-125
NVD status
Modified
Published
2022-11-02
CVE-2022-43995 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-43995 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-43995 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.