Novell Home

CVE-2008-3067

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-3067 at MITRE

Description

sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.

Novell/SUSE information

Novell Bugzilla entry: 397370

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • sudo >= 1.6.9p2-23.2

© 2012 Novell