VulnerabilityAnalyzed
CVE-2021-3156
Sudo Heap-Based Buffer Overflow Vulnerability
KEVHIGH 7.8EPSS 100.0%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 27 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.97% probability · 100th percentile
- CISA KEV
- Listed 6 April 2022 · due 27 April 2022
- Weakness
- CWE-193
- Affected
- sudo project/sudo · fedoraproject/fedora · debian/debian linux · netapp/active iq unified manager · netapp/cloud backup · netapp/hci management node · netapp/oncommand unified manager core package · netapp/ontap select deploy administration utility · netapp/ontap tools · netapp/solidfire · mcafee/web gateway · synology/diskstation manager unified controller · synology/diskstation manager · synology/skynas firmware · synology/vs960hd firmware · beyondtrust/privilege management for mac · beyondtrust/privilege management for unix\/linux · oracle/micros compact workstation 3 firmware · oracle/micros es400 firmware · oracle/micros kitchen display system firmware · +4 more
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-3156
References
- http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Feb/42Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2021/Jan/79Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Feb/3Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/26/3Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/27/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/27/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/02/15/1Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/09/14/2Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2024/01/30/6Exploit, Mailing List
- http://www.openwall.com/lists/oss-security/2024/01/30/8Mailing List
- https://kc.mcafee.com/corporate/index?page=content&id=SB10348Broken Link, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00022.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/Mailing List, Release Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/Mailing List, Release Notes
- https://security.gentoo.org/glsa/202101-33Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210128-0001/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210128-0002/Third Party Advisory
- https://support.apple.com/kb/HT212177Third Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcMThird Party Advisory
- https://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerabilityThird Party Advisory
- https://www.debian.org/security/2021/dsa-4839Third Party Advisory
- https://www.kb.cert.org/vuls/id/794544Third Party Advisory, US Government Resource
- https://www.openwall.com/lists/oss-security/2021/01/26/3Exploit, Mailing List, Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.