CVE-2019-18634 is a stack-based buffer overflow vulnerability affecting Sudo versions before 1.8.26, specifically when the non-default pwfeedback option is enabled in /etc/sudoers, as is the case in Linux Mint and elementary OS. An authenticated local attacker can trigger this vulnerability by providing a long string to the stdin of the getln() function, potentially leading to privilege escalation. This vulnerability has a CVSS score of 7.8 (High) due to its local attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, proof-of-concept exploits are publicly available on ExploitDB, and it has garnered significant community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.7.1, < 1.8.26CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.