← Back

CVE-2021-3156

Published: Jan 26, 2021Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

Affected (32)

Show all products
1 product
Sudo
1 product
Fedora
1 product
Debian Linux
7 products
Active Iq Unified Manager
Cloud Backup
Hci Management Node
Ontap Tools
Solidfire
1 product
Web Gateway
4 products
Diskstation Manager
Skynas Firmware
Vs960hd Firmware
2 products
Privilege Management For Mac
7 products
Micros Es400 Firmware
Micros Workstation 5a Firmware
Micros Workstation 6 Firmware
Tekelec Platform Distribution
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Sudo Project
From 1.8.2 to 1.8.32
From 1.9.0 to 1.9.5
Version 1.9.5
Version 1.9.5 patch1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration D
7 vulnerable
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Version 10.0.4
Version 8.2.17
Version 9.2.8
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.2
Version 3.0
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Synology
Skynas
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Synology
Vs960hd
All versions
Configuration I
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 21.1.1
Before 10.3.2-10
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 310
Running on/withPlatform Versions
Oracle
Micros Compact Workstation 3
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 400 to 410
Running on/withPlatform Versions
Oracle
Micros Es400
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 210
Running on/withPlatform Versions
Oracle
Micros Kitchen Display System
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 5a
Running on/withPlatform Versions
Oracle
Micros Workstation 5a
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 610 to 655
Running on/withPlatform Versions
Oracle
Micros Workstation 6
All versions
Configuration O
3 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
From 10.3.0.0.0 to 10.3.0.2.1
From 10.4.0.1.0 to 10.4.0.3.1
From 7.4.0 to 7.7.1

References (68)

Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
ExploitMailing List
Source: cve@mitre.org
Broken LinkThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Release Notes
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.