GHSA-c978-wq47-pvvw · Severity: low · Ecosystem: rust — sudo-rs: Partial password reveal is possible after timeout
sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not press return for an extended period, a password timeout may occur. When this happens, the keystrokes that were entered are echoed back to the console. This could reveal partial password information, possibly exposing history files when not carefully handled by the user and on screen, usable for Social Engineering or Pass-By attacks. Version 0.2.10 fixes the issue.
Conclusion & alert: CVE-2025-64170 is rated Low Risk (15.7/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.01%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-13 | — | 0.01% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.8 | 3.1 | LOW |
|
0.1 | 3.6 | [email protected] |
GHSA-c978-wq47-pvvw · Severity: low · Ecosystem: rust — sudo-rs: Partial password reveal is possible after timeout
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-64170 not yet assigned priority: Debian including 1 source packages (rust-sudo-rs), 3 status rows across 3 suites (forky, sid, trixie): resolved 3. | https://security-tracker.debian.org/tracker/CVE-2025-64170 |
ubuntu
|
medium | CVE-2025-64170 medium priority: Ubuntu including 1 source packages (rust-sudo-rs), 5 status rows across 5 suites (jammy, noble, plucky, questing, upstream): not-affected 2, released 2, DNE 1. | https://ubuntu.com/security/CVE-2025-64170 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||