7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Affected (32)
Show all products
Sudo Project: Sudo · Fedoraproject: Fedora · Debian: Debian Linux · Netapp: Active Iq Unified Manager, Cloud Backup, Hci Management Node, Oncommand Unified Manager Core Package, Ontap Select Deploy Administration Utility, Ontap Tools, Solidfire · Mcafee: Web Gateway · Synology: Diskstation Manager, Diskstation Manager Unified Controller, Skynas Firmware, Vs960hd Firmware · Beyondtrust: Privilege Management For Mac, Privilege Management For Unix/linux · Oracle: Micros Compact Workstation 3 Firmware, Micros Es400 Firmware, Micros Kitchen Display System Firmware, Micros Workstation 5a Firmware, Micros Workstation 6 Firmware, Communications Performance Intelligence Center, Tekelec Platform Distribution
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.8.2 to 1.8.32 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 32 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Version 9 | |
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0.4 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2 | |
| Version 3.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Synology Skynas | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Synology Vs960hd | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 21.1.1 | |
| Before 10.3.2-10 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 310 |
| Running on/with | Platform Versions |
|---|---|
Oracle Micros Compact Workstation 3 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 400 to 410 |
| Running on/with | Platform Versions |
|---|---|
Oracle Micros Es400 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 210 |
| Running on/with | Platform Versions |
|---|---|
Oracle Micros Kitchen Display System | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5a |
| Running on/with | Platform Versions |
|---|---|
Oracle Micros Workstation 5a | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 610 to 655 |
| Running on/with | Platform Versions |
|---|---|
Oracle Micros Workstation 6 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.3.0.0.0 to 10.3.0.2.1 | |
| From 7.4.0 to 7.7.1 |
References (68)
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Broken LinkThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListRelease Notes
Source: cve@mitre.org
Mailing ListRelease Notes
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.