Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
{
"versions": [
{
"introduced": "1.8.2"
},
{
"fixed": "1.8.32"
},
{
"introduced": "1.9.0"
},
{
"fixed": "1.9.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.5-NA"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.5-patch1"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3156.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.2.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "21.1.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.3.2-10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "310"
}
]
},
{
"events": [
{
"introduced": "400"
},
{
"last_affected": "410"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "210"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5a"
}
]
},
{
"events": [
{
"introduced": "610"
},
{
"last_affected": "655"
}
]
},
{
"events": [
{
"introduced": "10.3.0.0.0"
},
{
"last_affected": "10.3.0.2.1"
}
]
},
{
"events": [
{
"introduced": "10.4.0.1.0"
},
{
"last_affected": "10.4.0.3.1"
}
]
},
{
"events": [
{
"introduced": "7.4.0"
},
{
"last_affected": "7.7.1"
}
]
}
]