CVE-2021-3156
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-04-06Remediation due 2022-04-27
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
7.8
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2021-01-26
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-193
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sudo_project | sudo | >= 1.8.2, < 1.8.32 |
| sudo_project | sudo | >= 1.9.0, < 1.9.5 |
| sudo_project | sudo | 1.9.5 |
| sudo_project | sudo | 1.9.5 |
| fedoraproject | fedora | 32 |
| fedoraproject | fedora | 33 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| netapp | active_iq_unified_manager | all versions |
| netapp | cloud_backup | all versions |
| netapp | hci_management_node | all versions |
| netapp | oncommand_unified_manager_core_package | all versions |
| netapp | ontap_select_deploy_administration_utility | all versions |
| netapp | ontap_tools | 9 |
| netapp | solidfire | all versions |
| mcafee | web_gateway | 8.2.17 |
| mcafee | web_gateway | 9.2.8 |
| mcafee | web_gateway | 10.0.4 |
| synology | diskstation_manager_unified_controller | 3.0 |
| synology | diskstation_manager | 6.2 |
| synology | skynas_firmware | all versions |
| synology | skynas | all versions |
| synology | vs960hd_firmware | all versions |
| synology | vs960hd | all versions |
| beyondtrust | privilege_management_for_mac | < 21.1.1 |
| beyondtrust | privilege_management_for_unix/linux | < 10.3.2-10 |
| oracle | micros_compact_workstation_3_firmware | 310 |
| oracle | micros_compact_workstation_3 | all versions |
| oracle | micros_es400_firmware | >= 400, <= 410 |
| oracle | micros_es400 | all versions |
| oracle | micros_kitchen_display_system_firmware | 210 |
| oracle | micros_kitchen_display_system | all versions |
| oracle | micros_workstation_5a_firmware | 5a |
| oracle | micros_workstation_5a | all versions |
| oracle | micros_workstation_6_firmware | >= 610, <= 655 |
| oracle | micros_workstation_6 | all versions |
| oracle | communications_performance_intelligence_center | >= 10.3.0.0.0, <= 10.3.0.2.1 |
| oracle | communications_performance_intelligence_center | >= 10.4.0.1.0, <= 10.4.0.3.1 |
| oracle | tekelec_platform_distribution | >= 7.4.0, <= 7.7.1 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/161160/Sudo-Heap-Based-Buffer-Overflow.html
- http://packetstormsecurity.com/files/161230/Sudo-Buffer-Overflow-Privilege-Escalation.html
- http://packetstormsecurity.com/files/161270/Sudo-1.9.5p1-Buffer-Overflow-Privilege-Escalation.html
- http://packetstormsecurity.com/files/161293/Sudo-1.8.31p2-1.9.5p1-Buffer-Overflow.html
- http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html
- http://seclists.org/fulldisclosure/2021/Feb/42
- http://seclists.org/fulldisclosure/2021/Jan/79
- http://seclists.org/fulldisclosure/2024/Feb/3
- http://www.openwall.com/lists/oss-security/2021/01/26/3
- http://www.openwall.com/lists/oss-security/2021/01/27/1
- http://www.openwall.com/lists/oss-security/2021/01/27/2
- http://www.openwall.com/lists/oss-security/2021/02/15/1
- http://www.openwall.com/lists/oss-security/2021/09/14/2
- http://www.openwall.com/lists/oss-security/2024/01/30/6
- http://www.openwall.com/lists/oss-security/2024/01/30/8
- https://kc.mcafee.com/corporate/index?page=content&id=SB10348
- https://lists.debian.org/debian-lts-announce/2021/01/msg00022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CALA5FTXIQBRRYUA2ZQNJXB6OQMAXEII/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LHXK6ICO5AYLGFK2TAX5MZKUXTUKWOJY/
- https://security.gentoo.org/glsa/202101-33
- https://security.netapp.com/advisory/ntap-20210128-0001/
- https://security.netapp.com/advisory/ntap-20210128-0002/
- https://support.apple.com/kb/HT212177
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM
- https://www.beyondtrust.com/blog/entry/security-advisory-privilege-management-for-unix-linux-pmul-basic-and-privilege-management-for-mac-pmm-affected-by-sudo-vulnerability
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-3156