Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w5vh-2923-gp5c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character:

Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character:

Ссылки

EPSS

Процентиль: 100%
0.92309
Критический

7.8 High

CVSS3

Дефекты

CWE-193
CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CVSS3: 7.8
redhat
около 5 лет назад

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CVSS3: 7.8
nvd
около 5 лет назад

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CVSS3: 7.8
debian
около 5 лет назад

Sudo before 1.9.5p2 contains an off-by-one error that can result in a ...

suse-cvrf
почти 5 лет назад

Security update for sudo

EPSS

Процентиль: 100%
0.92309
Критический

7.8 High

CVSS3

Дефекты

CWE-193
CWE-787