CVE-2008-3067

SUSE openSUSE 10.3 - Password Exposure via Uncleared stdin Buffer

Title source: llm
STIX 2.1

Description

sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43618

Scores

EPSS 0.0006
EPSS Percentile 17.8%

Details

CWE
CWE-255
Status published
Products (1)
suse/opensuse 10.3
Published Jul 07, 2008
Tracked Since Feb 18, 2026