CVE-2019-18634

In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
sudo_projectsudo
1.7.1 ≤
𝑥
< 1.8.26
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sudo
bookworm
1.9.13p3-1+deb12u1
fixed
bullseye
1.9.5p2-3+deb11u1
fixed
bullseye (security)
1.9.5p2-3+deb11u1
fixed
sid
1.9.16-2
fixed
trixie
1.9.16-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sudo
bionic
Fixed 1.8.21p2-3ubuntu1.2
released
eoan
Fixed 1.8.27-1ubuntu4.1
released
trusty
Fixed 1.8.9p5-1ubuntu1.5+esm3
released
xenial
Fixed 1.8.16-0ubuntu1.9
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
sudo
suse enterprise desktop 15
1.8.22-4.9.1
fixed
suse enterprise desktop 15 SP1
1.8.22-4.9.1
fixed
suse enterprise desktop 15 SP2
1.8.22-4.9.1
fixed
suse enterprise desktop 15 SP4
1.9.9-150400.2.5
fixed
suse enterprise sap 15
1.8.22-4.9.1
fixed
suse enterprise sap 15 SP1
1.8.22-4.9.1
fixed
suse enterprise sap 15 SP2
1.8.22-4.9.1
fixed
suse enterprise sap 15 SP4
1.9.9-150400.2.5
fixed
suse enterprise server 15
1.8.22-4.9.1
fixed
suse enterprise server 15 SP1
1.8.22-4.9.1
fixed
suse enterprise server 15 SP2
1.8.22-4.9.1
fixed
suse enterprise server 15 SP4
1.9.9-150400.2.5
fixed
sudo-devel
suse enterprise desktop 15
1.8.22-4.9.1
fixed
suse enterprise desktop 15 SP1
1.8.22-4.9.1
fixed
suse enterprise desktop 15 SP2
1.8.22-4.9.1
fixed
suse enterprise desktop 15 SP4
1.9.9-150400.2.5
fixed
suse enterprise sap 15
1.8.22-4.9.1
fixed
suse enterprise sap 15 SP1
1.8.22-4.9.1
fixed
suse enterprise sap 15 SP2
1.8.22-4.9.1
fixed
suse enterprise sap 15 SP4
1.9.9-150400.2.5
fixed
suse enterprise server 15
1.8.22-4.9.1
fixed
suse enterprise server 15 SP1
1.8.22-4.9.1
fixed
suse enterprise server 15 SP2
1.8.22-4.9.1
fixed
suse enterprise server 15 SP4
1.9.9-150400.2.5
fixed
sudo-plugin-python
suse enterprise desktop 15 SP4
1.9.9-150400.2.5
fixed
suse enterprise sap 15 SP4
1.9.9-150400.2.5
fixed
suse enterprise server 15 SP4
1.9.9-150400.2.5
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
sudo
RHEL 6
0:1.8.6p3-29.el6_10.3
fixed
RHEL 7
0:1.8.23-4.el7_7.2
fixed
sudo-devel
RHEL 6
0:1.8.6p3-29.el6_10.3
fixed
RHEL 7
0:1.8.23-4.el7_7.2
fixed
References