Lucene search

K
f5F5F5:K86488846
HistoryJan 29, 2021 - 12:00 a.m.

K86488846 : Sudo vulnerability CVE-2021-3156

2021-01-2900:00:00
my.f5.com
81

8.2 High

AI Score

Confidence

High

0.97 High

EPSS

Percentile

99.7%

Security Advisory Description

Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via “sudoedit -s” and a command-line argument that ends with a single backslash character. (CVE-2021-3156)

Impact

A local attacker can exploit the vulnerability to escalate their privileges on a vulnerable system giving them access to read or modify sensitive information or cause a denial-of-service (DoS).