#VU118370 Information disclosure in sudo-rs - CVE-2025-64170

 

#VU118370 Information disclosure in sudo-rs - CVE-2025-64170

Published: November 12, 2025


Vulnerability identifier: #VU118370
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-64170
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
sudo-rs
Software vendor:
Prossimo

Description

The vulnerability allows an attacker to gain access to potentially sensitive information.

The vulnerability exists due to the way timeouts are implemented. When typing partial passwords but not pressing return for a long time, a password timeout can occur. This results in symbols entered as password to be displayed in the console. An attacker with physical access to the system can observe entered data in the console. 


Remediation

Install updates from vendor's website.

External links