CVE-2022-43995 - CVE House
Back to Database
Status published Unknown CVE-2022-43995

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains...

Vulnerability Description

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler, and processor architecture.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-43995

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

sudo project

View all reports →

Affected Software

sudo
Vulnerable Versions:
1.8.0, 1.9.12

Timeline

Official Publish: November 2nd, 2022
Last Modified: May 5th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.