Vulnerabilities > Sudo Project > Sudo > 1.9.13

DATE CVE VULNERABILITY TITLE RISK
2023-12-22 CVE-2023-42465 Unspecified vulnerability in Sudo Project Sudo
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value), and because the values do not resist flips of a single bit.
local
high complexity
sudo-project
7.0
2023-02-28 CVE-2023-27320 Double Free vulnerability in multiple products
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
network
low complexity
sudo-project fedoraproject CWE-415
7.2