CVE-2023-42465
22.12.2023, 16:15
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sudo_project | sudo | 𝑥 < 1.9.15 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| sudo |
| ||||
| sudo-devel |
| ||||
| sudo-plugin-python |
|
Red Hat Enterprise Linux Releases
References