Логотип exploitDog
bind:CVE-2025-64170
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64170

Количество 4

Количество 4

ubuntu логотип

CVE-2025-64170

3 месяца назад

sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not press return for an extended period, a password timeout may occur. When this happens, the keystrokes that were entered are echoed back to the console. This could reveal partial password information, possibly exposing history files when not carefully handled by the user and on screen, usable for Social Engineering or Pass-By attacks. Version 0.2.10 fixes the issue.

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2025-64170

3 месяца назад

sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not press return for an extended period, a password timeout may occur. When this happens, the keystrokes that were entered are echoed back to the console. This could reveal partial password information, possibly exposing history files when not carefully handled by the user and on screen, usable for Social Engineering or Pass-By attacks. Version 0.2.10 fixes the issue.

CVSS3: 3.8
EPSS: Низкий
debian логотип

CVE-2025-64170

3 месяца назад

sudo-rs is a memory safe implementation of sudo and su written in Rust ...

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-c978-wq47-pvvw

3 месяца назад

sudo-rs: Partial password reveal is possible after timeout

CVSS3: 3.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-64170

sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not press return for an extended period, a password timeout may occur. When this happens, the keystrokes that were entered are echoed back to the console. This could reveal partial password information, possibly exposing history files when not carefully handled by the user and on screen, usable for Social Engineering or Pass-By attacks. Version 0.2.10 fixes the issue.

CVSS3: 3.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-64170

sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not press return for an extended period, a password timeout may occur. When this happens, the keystrokes that were entered are echoed back to the console. This could reveal partial password information, possibly exposing history files when not carefully handled by the user and on screen, usable for Social Engineering or Pass-By attacks. Version 0.2.10 fixes the issue.

CVSS3: 3.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-64170

sudo-rs is a memory safe implementation of sudo and su written in Rust ...

CVSS3: 3.8
0%
Низкий
3 месяца назад
github логотип
GHSA-c978-wq47-pvvw

sudo-rs: Partial password reveal is possible after timeout

CVSS3: 3.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу