Sudo.Heap.Overflow.CVE-2021-3156.Privilege.Elevation
Description
This indicates an attack attempt to exploit an Elevation Of Privilege Vulnerability in the Sudo
The vulnerability is due to an error in the vulnerable application when handling a maliciously crafted input. A remote attacker may be able to exploit this to leverage their privileges on vulnerable systems.
Affected Products
All POSIX systems that includes sudo (eg. Linux) since July 2011 (commit 8255ed69).
Sudo versions-
1.8.2 to 1.8.31p2
1.9.0 to 1.9.5p1, in their default configuration.
Confirmed OS-
Ubuntu 16.04
Ubuntu 20.04
Debian 10
Fedora 33
Arch Linux 20210115
Other OS might be impacted.
Impact
Privilege Escalation: Remote attackers can leverage their privileges on vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2022-08-16 | 21.375 | Sig Added |
2022-08-15 | 21.373 | Sig Added |
2021-03-02 | 17.025 | Default_action:pass:drop |
2021-02-15 | 17.016 | Sig Added |
2021-02-08 | 17.012 | Sig Added |
2021-02-04 | 17.011 |