#VU118370 Information disclosure in sudo-rs - CVE-2025-64170
Published: November 12, 2025
sudo-rs
Prossimo
Description
The vulnerability allows an attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way timeouts are implemented. When typing partial passwords but not pressing return for a long time, a password timeout can occur. This results in symbols entered as password to be displayed in the console. An attacker with physical access to the system can observe entered data in the console.