Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
References
Link Providers
http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html cve-icon cve-icon
http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html cve-icon cve-icon
http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html cve-icon cve-icon
http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html cve-icon cve-icon
http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html cve-icon cve-icon
http://seclists.org/fulldisclosure/2021/Feb/42 cve-icon cve-icon
http://seclists.org/fulldisclosure/2021/Jan/79 cve-icon cve-icon
http://seclists.org/fulldisclosure/2024/Feb/3 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2021/01/26/3 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2021/01/27/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2021/01/27/2 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2021/02/15/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2021/09/14/2 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2024/01/30/6 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2024/01/30/8 cve-icon cve-icon
https://kc.mcafee.com/corporate/index?page=content&id=SB10348 cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/ cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2021-3156 cve-icon
https://security.gentoo.org/glsa/202101-33 cve-icon cve-icon
https://security.netapp.com/advisory/ntap-20210128-0001/ cve-icon cve-icon
https://security.netapp.com/advisory/ntap-20210128-0002/ cve-icon cve-icon
https://support.apple.com/kb/HT212177 cve-icon cve-icon
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM cve-icon cve-icon
https://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerability cve-icon cve-icon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog cve-icon
https://www.cve.org/CVERecord?id=CVE-2021-3156 cve-icon
https://www.debian.org/security/2021/dsa-4839 cve-icon cve-icon
https://www.kb.cert.org/vuls/id/794544 cve-icon cve-icon
https://www.openwall.com/lists/oss-security/2021/01/26/3 cve-icon cve-icon
https://www.oracle.com//security-alerts/cpujul2021.html cve-icon cve-icon
https://www.oracle.com/security-alerts/cpuapr2022.html cve-icon cve-icon
https://www.oracle.com/security-alerts/cpuoct2021.html cve-icon cve-icon
https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt cve-icon
https://www.sudo.ws/alerts/unescape_overflow.html cve-icon
https://www.sudo.ws/stable.html#1.9.5p2 cve-icon cve-icon
https://www.synology.com/security/advisory/Synology_SA_21_02 cve-icon cve-icon
https://www.vicarius.io/vsociety/posts/sudoedit-pwned-cve-2021-3156 cve-icon cve-icon
History

Wed, 18 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
References

Wed, 14 Aug 2024 01:00:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-01-26T00:00:00

Updated: 2024-09-18T16:41:27.031257

Reserved: 2021-01-15T00:00:00

Link: CVE-2021-3156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-26T21:15:12.987

Modified: 2024-09-18T17:15:13.843

Link: CVE-2021-3156

cve-icon Redhat

Severity : Important

Publid Date: 2021-01-26T18:00:00Z

Links: CVE-2021-3156 - Bugzilla