Search CVE reports


Toggle filters

1 – 10 of 52 results


CVE-2025-46718

Medium priority
Needs evaluation

sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag....

1 affected package

rust-sudo-rs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-sudo-rs Needs evaluation Not in release Not in release
Show less packages

CVE-2025-46717

Medium priority
Needs evaluation

sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very limited) sudo privileges can determine whether files exists in folders that they otherwise cannot access using...

1 affected package

rust-sudo-rs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-sudo-rs Needs evaluation Not in release Not in release
Show less packages

CVE-2023-7090

Medium priority
Not affected

A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts...

1 affected package

sudo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sudo Not affected Not affected Not affected
Show less packages

CVE-2023-42465

Medium priority
Not affected

Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because...

1 affected package

sudo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sudo Not affected Not affected Not affected
Show less packages

CVE-2023-42456

Medium priority

Not in release

Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo attempt, but instead only requiring authentication every once in a while in every terminal or process group. Only...

1 affected package

rust-sudo-rs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-sudo-rs Not in release Not in release Not in release
Show less packages

CVE-2023-28487

Medium priority

Some fixes available 10 of 11

Sudo before 1.9.13 does not escape control characters in sudoreplay output.

1 affected package

sudo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sudo Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-28486

Medium priority

Some fixes available 10 of 11

Sudo before 1.9.13 does not escape control characters in log messages.

1 affected package

sudo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sudo Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-27320

Medium priority
Fixed

Sudo before 1.9.13p2 has a double free in the per-command chroot feature.

1 affected package

sudo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sudo Fixed Not affected Not affected
Show less packages

CVE-2023-22809

Medium priority
Fixed

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the...

1 affected package

sudo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sudo Fixed Fixed Fixed
Show less packages

CVE-2022-43995

Medium priority
Not affected

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with...

1 affected package

sudo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
sudo Not affected Not affected Not affected
Show less packages