Oval Definition:oval:org.opensuse.security:def:202243995
Revision Date:2023-06-22Version:1
Title:CVE-2022-43995
Description:

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler, and processor architecture.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-43995
SUSE CVE-2022-43995
SUSE-CU-2022:3020-1
SUSE-CU-2022:3067-1
SUSE-CU-2022:3068-1
SUSE-IU-2022:1124-1
SUSE-IU-2022:1130-1
SUSE-IU-2022:1131-1
SUSE-IU-2022:1132-1
SUSE-IU-2022:1133-1
SUSE-IU-2022:1134-1
SUSE-IU-2022:1148-1
SUSE-SU-2022:3886-1
SUSE-SU-2022:3938-1
SUSE-SU-2022:4001-1
SUSE-SU-2022:4077-1
SUSE-SU-2022:4240-1
SUSE-SU-2022:4280-1
SUSE-CU-2023:496-1
SUSE-CU-2023:500-1
SUSE-CU-2023:511-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.3 is installed
  • AND sudo-1.9.9-150400.4.6.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • sudo-1.9.12p1-150500.5.1 is installed
  • OR sudo-devel-1.9.12p1-150500.5.1 is installed
  • OR sudo-plugin-python-1.9.12p1-150500.5.1 is installed
  • BACK