HIGH

CVE-2021-3156

Fedoraproject Fedora 2021-01-26 CVSS v3.1
CVSS
7.8
KEV

Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Summary dbcve.org

Sudo before 1.9.5p2 contains an off-by-one error in argument processing that leads to a heap-based buffer overflow. When sudoedit is invoked with the -s flag and a command-line argument ending with a single backslash character, the boundary check is bypassed, allowing an attacker to overwrite adjacent heap memory and gain root privileges.

Mitigation

Upgrade sudo to version 1.9.5p2 or later to patch the off-by-one error. Alternatively, restrict sudo/sudoedit access or monitor for exploitation attempts using the -s flag with backslash-terminated arguments.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-193

EPSS Score

99.96%
Probability of exploitation in next 30 days
100th percentile

References

http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html Exploit, Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html Exploit, Third Party Advisory, VDB Entry http://seclists.org/fulldisclosure/2021/Feb/42 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2021/Jan/79 Exploit, Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Feb/3 Exploit, Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/01/26/3 Exploit, Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/01/27/1 Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/01/27/2 Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/02/15/1 Exploit, Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2021/09/14/2 Mailing List, Patch, Third Party Advisory http://www.openwall.com/lists/oss-security/2024/01/30/6 Exploit, Mailing List http://www.openwall.com/lists/oss-security/2024/01/30/8 Mailing List https://kc.mcafee.com/corporate/index?page=content&id=SB10348 Broken Link, Third Party Advisory https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html Mailing List, Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/ Mailing List, Release Notes https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/ Mailing List, Release Notes https://security.gentoo.org/glsa/202101-33 Third Party Advisory https://security.netapp.com/advisory/ntap-20210128-0001/ Third Party Advisory https://security.netapp.com/advisory/ntap-20210128-0002/ Third Party Advisory https://support.apple.com/kb/HT212177 Third Party Advisory https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM Third Party Advisory https://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerability Third Party Advisory https://www.debian.org/security/2021/dsa-4839 Third Party Advisory https://www.kb.cert.org/vuls/id/794544 Third Party Advisory, US Government Resource https://www.openwall.com/lists/oss-security/2021/01/26/3 Exploit, Mailing List, Third Party Advisory https://www.oracle.com//security-alerts/cpujul2021.html Patch, Third Party Advisory https://www.oracle.com/security-alerts/cpuapr2022.html Patch, Third Party Advisory https://www.oracle.com/security-alerts/cpuoct2021.html Patch, Third Party Advisory https://www.sudo.ws/stable.html#1.9.5p2 Release Notes https://www.synology.com/security/advisory/Synology_SA_21_02 Third Party Advisory https://www.vicarius.io/vsociety/posts/sudoedit-pwned-cve-2021-3156 Exploit, Third Party Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3156 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE