CVE-2023-42465

    Dashboard / Vulnerabilities / CVE-2023-42465

    CVE-2023-42465

    Published: 22 Dec 2023Last Modified: 12 Aug 2026

    Summary:

    Details: Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v1.9.14p3
    v1.9.14p2
    v1.9.14p1
    v1.9.14
    v1.9.13p3
    v1.9.13p2
    v1.9.13p1
    v1.9.13
    v1.9.12p2
    v1.9.12p1
    v1.9.12
    v1.9.11p3
    v1.9.11p2
    v1.9.11p1
    v1.9.11
    v1.9.10
    v1.9.9
    v1.9.8p2
    v1.9.8p1
    v1.9.8
    v1.9.7p2
    v1.9.7p1
    v1.9.7
    v1.9.6p1
    v1.9.6
    v1.9.5p2
    v1.9.5p1
    v1.9.5
    v1.9.4p2
    v1.9.4p1
    v1.9.4
    v1.9.3p1
    v1.9.3
    v1.9.2
    v1.9.1
    v1.9.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-42465 | CVE-DB