CyberSec.Space Logo
返回 CVE 浏览器

CVE-2021-3156

🔥 Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score35.4610%
EPSS Percentile86.25th
Published2021-01-26
Last Modified2025-11-10
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Affected Platforms (CPE)

📦
Sudo Project

Sudo

>= 1.8.2 and < 1.8.32>= 1.9.0 and < 1.9.5= 1.9.5
💻
Fedoraproject

Fedora

= 32= 33
💻
Debian

Debian Linux

= 9.0= 10.0
📦
Netapp

Active Iq Unified Manager

All versions

References & Advisories

相关漏洞威胁