CVE-2021-3156

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
sudo_projectsudo
1.8.2 ≤
𝑥
< 1.8.32
sudo_projectsudo
1.9.0 ≤
𝑥
< 1.9.5
sudo_projectsudo
1.9.5
sudo_projectsudo
1.9.5:patch1
debiandebian_linux
9.0
debiandebian_linux
10.0
netappactive_iq_unified_manager
-
netappcloud_backup
-
netapphci_management_node
-
netapponcommand_unified_manager_core_package
-
netappontap_select_deploy_administration_utility
-
netappsolidfire
-
mcafeeweb_gateway
8.2.17
mcafeeweb_gateway
9.2.8
mcafeeweb_gateway
10.0.4
synologydiskstation_manager_unified_controller
3.0
synologydiskstation_manager
6.2
synologyskynas_firmware
-
synologyvs960hd_firmware
-
beyondtrustprivilege_management_for_mac
𝑥
< 21.1.1
beyondtrustprivilege_management_for_unix\/linux
𝑥
< 10.3.2-10
oraclemicros_es400_firmware
400 ≤
𝑥
≤ 410
oraclemicros_workstation_6_firmware
610 ≤
𝑥
≤ 655
oraclecommunications_performance_intelligence_center
10.3.0.0.0 ≤
𝑥
≤ 10.3.0.2.1
oraclecommunications_performance_intelligence_center
10.4.0.1.0 ≤
𝑥
≤ 10.4.0.3.1
oracletekelec_platform_distribution
7.4.0 ≤
𝑥
≤ 7.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sudo
bullseye (security)
1.9.5p2-3+deb11u1
fixed
bullseye
1.9.5p2-3+deb11u1
fixed
bookworm
1.9.13p3-1+deb12u1
fixed
sid
1.9.16-2
fixed
trixie
1.9.16-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sudo
groovy
Fixed 1.9.1-1ubuntu1.1
released
focal
Fixed 1.8.31-1ubuntu1.2
released
bionic
Fixed 1.8.21p2-3ubuntu1.4
released
xenial
Fixed 1.8.16-0ubuntu1.10
released
trusty
Fixed 1.8.9p5-1ubuntu1.5+esm6
released
References