VDB

DEBIAN-CVE-2023-42465

DEBIAN-CVE-2023-42465 PUBLISHED CVSS 7 HIGH

Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.

Risk Scores

CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:12sudo*, *, *
Debian:11sudo1.9.6-1, *, 1.9.10-3
Debian:14sudo0, 0, 0
Debian:13sudo0, 0, 0

Exploit Intelligence

Timeline

  • Dec 22, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›