Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-3156

Quick assessment

Affected
n/a n/a
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Sudo是一款使用于类Unix系统的,允许用户通过安全的方式使用特殊的权限执行命令的程序。 Sudo 1.9.5p2 之前版本存在缓冲区错误漏洞,攻击者可使用sudoedit -s和一个以单个反斜杠字符结束的命令行参数升级到root。

AI Predicted 7.8 Difficulty: Moderate KEV EPSS 99.30% · P100

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-3156

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Sudo 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sudo是一款使用于类Unix系统的,允许用户通过安全的方式使用特殊的权限执行命令的程序。 Sudo 1.9.5p2 之前版本存在缓冲区错误漏洞,攻击者可使用sudoedit -s和一个以单个反斜杠字符结束的命令行参数升级到root。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2021-3156

# POC Description Source Link Shenlong Link
1 None https://github.com/mr-r3b00t/CVE-2021-3156 POC Details
2 None https://github.com/nexcess/sudo_cve-2021-3156 POC Details
3 CVE-2021-3156 https://github.com/reverse-ex/CVE-2021-3156 POC Details
4 None https://github.com/unauth401/CVE-2021-3156 POC Details
5 CVE-2021-3156 https://github.com/ymrsmns/CVE-2021-3156 POC Details
6 This simple bash script will patch the recently discovered sudo heap overflow vulnerability. https://github.com/elbee-cyber/CVE-2021-3156-PATCHER POC Details
7 1day research effort https://github.com/kernelzeroday/CVE-2021-3156-Baron-Samedit POC Details
8 cve-2021-3156;sudo堆溢出漏洞;漏洞检测 https://github.com/yaunsky/cve-2021-3156 POC Details
9 None https://github.com/baka9moe/CVE-2021-3156-Exp POC Details
10 CVE-2021-3156 https://github.com/ph4ntonn/CVE-2021-3156 POC Details
11 None https://github.com/binw2018/CVE-2021-3156-SCRIPT POC Details
12 None https://github.com/freeFV/CVE-2021-3156 POC Details
13 Notes regarding CVE-2021-3156: Heap-Based Buffer Overflow in Sudo https://github.com/mbcrump/CVE-2021-3156 POC Details
14 PoC for CVE-2021-3156 (sudo heap overflow) https://github.com/stong/CVE-2021-3156 POC Details
15 checking CVE-2021-3156 vulnerability & patch script https://github.com/nobodyatall648/CVE-2021-3156 POC Details
16 None https://github.com/blasty/CVE-2021-3156 POC Details
17 None https://github.com/teamtopkarl/CVE-2021-3156 POC Details
18 复现别人家的CVEs系列 https://github.com/Q4n/CVE-2021-3156 POC Details
19 Description Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. https://github.com/kal1gh0st/CVE-2021-3156 POC Details
20 A docker environment to research CVE-2021-3156 https://github.com/apogiatzis/docker-CVE-2021-3156 POC Details
21 a simple script to patch CVE-2021-3156 (heap based buffer overflow via sudo). https://github.com/voidlsd/CVE-2021-3156 POC Details
22 Patch Script for CVE-2021-3156 Heap Overflow https://github.com/Ashish-dawani/CVE-2021-3156-Patch POC Details
23 None https://github.com/SantiagoSerrao/ScannerCVE-2021-3156 POC Details
24 CTF for HDE 64 students at See Security College. Exploit a JWT (web part) & CVE-2021-3156 (LPE part). https://github.com/DanielAzulayy/CTF-2021 POC Details
25 None https://github.com/cdeletre/Serpentiel-CVE-2021-3156 POC Details
26 CVE-2021-3156 Vagrant Lab https://github.com/dinhbaouit/CVE-2021-3156 POC Details
27 Root shell PoC for CVE-2021-3156 https://github.com/CptGibbon/CVE-2021-3156 POC Details
28 Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied https://github.com/perlun/sudo-1.8.3p1-patched POC Details
29 None https://github.com/1N53C/CVE-2021-3156-PoC POC Details
30 CVE-2021-3156: Sudo heap overflow exploit for Debian 10 https://github.com/0xdevil/CVE-2021-3156 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-3156

登录查看更多情报信息。

Vendor Advisories for CVE-2021-3156 (9)

Exploits & Public PoCs for CVE-2021-3156 (3)

Mailing List Discussions for CVE-2021-3156 (13)

Security Blog Posts for CVE-2021-3156 (2)

Other References for CVE-2021-3156 (3)

Same Patch Batch · n/a · 2021-01-26 · 42 CVEs total

CVE-2021-22159 Proofpoint Insider Threat Management Server 安全漏洞
CVE-2020-8295 Nextcloud 资源管理错误漏洞
CVE-2020-23447 newbee-mall 跨站脚本漏洞
CVE-2020-23448 newbee-mall 授权问题漏洞
CVE-2020-23449 newbee-mall 访问控制错误漏洞
CVE-2020-35263 Egavilanmedia User Registration & Login System SQL注入漏洞
CVE-2020-13582 Micrium uC-HTTP 代码问题漏洞
CVE-2020-27274 Honeywell OPC UA Tunneller 代码问题漏洞
CVE-2020-27299 Honeywell OPC UA Tunneller 缓冲区错误漏洞
CVE-2020-27297 Honeywell OPC UA Tunneller 缓冲区错误漏洞
CVE-2020-27295 Honeywell OPC UA Tunneller 资源管理错误漏洞
CVE-2020-8293 Nextcloud 资源管理错误漏洞
CVE-2021-3308 Xen 安全漏洞
CVE-2021-3309 Wekan 信任管理问题漏洞
CVE-2021-26271 CKEditor 安全漏洞
CVE-2021-26272 CKEditor 安全漏洞
CVE-2020-23774 苏州华兆科技 Winmail 跨站脚本漏洞
CVE-2020-23776 苏州华兆科技 Winmail 代码问题漏洞
CVE-2021-3317 KLog 命令注入漏洞
CVE-2021-3165 SmartAgent 安全漏洞

Showing top 20 of 42 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-3156

No comments yet


Leave a comment