CVE-2008-3067: Low severity suse linux vulnerability
Published Jul 7, 2008
·Updated
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.
Affected Software
1 affected component
SUSE openSUSE=10.3
Event History
Jul 7, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3067?
CVE-2008-3067 is classified as a medium severity vulnerability.
2
How do I fix CVE-2008-3067?
To fix CVE-2008-3067, update to a patched version of sudo provided by SUSE or apply the recommended security patches.
3
Who is affected by CVE-2008-3067?
CVE-2008-3067 affects local users of SUSE openSUSE version 10.3.
4
What systems are impacted by CVE-2008-3067?
CVE-2008-3067 specifically impacts the SUSE openSUSE 10.3 operating system.
5
What type of attack vector is associated with CVE-2008-3067?
CVE-2008-3067 can allow localized users to potentially read sensitive password information due to improper buffer management.