CVE-2022-43995

Source
https://cve.org/CVERecord?id=CVE-2022-43995
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43995.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-43995
Downstream
Related
Published
2022-11-02T00:00:00Z
Modified
2026-07-22T02:08:41.951719Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler, and processor architecture.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/43xxx/CVE-2022-43995.json"
}
References

Affected packages

Git / github.com/millert/sudo

Affected ranges

Type
GIT
Repo
https://github.com/millert/sudo
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:sudo_project:sudo:1.9.12:-:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "1.8.0"
        },
        {
            "fixed": "1.9.12"
        },
        {
            "introduced": "1.9.12-NA"
        },
        {
            "last_affected": "1.9.12-NA"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}
Type
GIT
Repo
https://github.com/sudo-project/sudo
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:sudo_project:sudo:1.9.12:-:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "1.8.0"
        },
        {
            "fixed": "1.9.12"
        },
        {
            "introduced": "1.9.12-NA"
        },
        {
            "last_affected": "1.9.12-NA"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.9.12-NA
Other
SUDO_1_8_0
SUDO_1_9_0
SUDO_1_9_1
SUDO_1_9_10
SUDO_1_9_11
SUDO_1_9_11p1
SUDO_1_9_11p2
SUDO_1_9_11p3
SUDO_1_9_12
SUDO_1_9_2
SUDO_1_9_3
SUDO_1_9_3p1
SUDO_1_9_4
SUDO_1_9_4p1
SUDO_1_9_4p2
SUDO_1_9_5
SUDO_1_9_5p1
SUDO_1_9_5p2
SUDO_1_9_6
SUDO_1_9_6p1
SUDO_1_9_7
SUDO_1_9_7p1
SUDO_1_9_7p2
SUDO_1_9_8
SUDO_1_9_8p1
SUDO_1_9_8p2
SUDO_1_9_9
v1.*
v1.8.0
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.11p1
v1.9.11p2
v1.9.11p3
v1.9.2
v1.9.3
v1.9.3p1
v1.9.4
v1.9.4p1
v1.9.4p2
v1.9.5
v1.9.5p1
v1.9.5p2
v1.9.6
v1.9.6p1
v1.9.7
v1.9.7p1
v1.9.7p2
v1.9.8
v1.9.8p1
v1.9.8p2
v1.9.9

Database specific

vanir_signatures_modified
"2026-07-22T02:08:41Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337633252920991241112857162465452390298",
                "262853266045190752843127941413843408656",
                "61690952090159972777364936005601145194",
                "128035712224375988314427638006103912115",
                "94127008450240786502871837663103258118",
                "98733321982592306874869601466115003794",
                "8004731231940764953004213991397676849",
                "221443112049861906691759667364935375915",
                "113536667263124047403014320319250631257",
                "267568419315262234764733117499065506321",
                "181495643499762969102095757999593662642",
                "224122946542034265895270638157337010187",
                "26387421224791964521672678200805934154"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/sudo-project/sudo/commit/bd209b9f16fcd1270c13db27ae3329c677d48050",
        "id": "CVE-2022-43995-583b6dec",
        "target": {
            "file": "plugins/sudoers/auth/passwd.c"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 679.0,
            "function_hash": "98815895881217986653558569722860438731"
        },
        "signature_version": "v1",
        "source": "https://github.com/sudo-project/sudo/commit/bd209b9f16fcd1270c13db27ae3329c677d48050",
        "id": "CVE-2022-43995-773384c8",
        "target": {
            "function": "sudo_passwd_verify",
            "file": "plugins/sudoers/auth/passwd.c"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-43995.json"