CVE-2021-3156

Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via “sudoedit -s” and a command-line argument that ends with a single backslash character.

Summary:

Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via “sudoedit -s” and a command-line argument that ends with a single backslash character.

Reference Links(if available):

  • https://www.openwall.com/lists/oss-security/2021/01/26/3
  • https://www.sudo.ws/stable.html#1.9.5p2
  • http://www.openwall.com/lists/oss-security/2021/01/26/3
  • https://security.gentoo.org/glsa/202101-33
  • https://lists.fedoraproject.org/archives/list/[email protected]/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/
  • CVSS Score (if available)

    v2: / HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C

    v3: / HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

    Links to Exploits(if available)

  • https://github.com/offensive-security/exploitdb/blob/master/exploits/multiple/local/49521.py
  • https://github.com/offensive-security/exploitdb/blob/master/exploits/multiple/local/49522.c