CyberSec.Space Logo
Back to CVE Browser

CVE-2021-3156

πŸ”₯ Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score35.4610%
EPSS Percentile86.25th
Published2021-01-26
Last Modified2025-11-10
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Affected Platforms (CPE)

πŸ“¦
Sudo Project

Sudo

>= 1.8.2 and < 1.8.32>= 1.9.0 and < 1.9.5= 1.9.5
πŸ’»
Fedoraproject

Fedora

= 32= 33
πŸ’»
Debian

Debian Linux

= 9.0= 10.0
πŸ“¦
Netapp

Active Iq Unified Manager

All versions

References & Advisories

Related Vulnerabilities