CVE-2023-42465
CVSS 3.1 Score 7.0 of 10 (high)
Details
Published Dec 22, 2023
Updated: Feb 18, 2024
Summary
CVE-2023-42465 is a vulnerability affecting Sudo versions prior to 1.9.15. The issue stems from the application's logic that relies on not equating an error value instead of equating a success value. This quirk exposes Sudo to row hammer attacks, which could lead to authentication bypass or privilege escalation. The vulnerability arises due to the values not being resilient to a single-bit flip.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sudo Project Sudo
Affected Vendors
- Sudo Project