CVE-2021-3156, also known as "Baron Samedit," is a critical heap-based buffer overflow vulnerability in Sudo versions prior to 1.9.5p2, affecting numerous products including Debian, Fedora, and macOS. This flaw allows a local attacker to achieve root privilege escalation by exploiting an off-by-one error when using "sudoedit -s" with a specially crafted command-line argument. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered extensive community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.8.2, < 1.8.32CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* | ||
>= 1.9.0, < 1.9.5CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:*:*:*:*:*:*:*:* | ||
1.9.5CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:1.9.5:-:*:*:*:*:*:* | ||
1.9.5CPE matchmatch criteria | cpe:2.3:a:sudo_project:sudo:1.9.5:patch1:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021sudo: Heap buffer overflow in argument parsing
Jan 26, 2021Sudo Privilege Escalation Vulnerability (Baron Samedit)
Jan 1, 2021Sudo Privilege Escalation Vulnerability (Baron Samedit)
A vulnerability was recently discovered in the Linux utility sudo, described in CVE-2021-3156, that may allow an attacker with unprivileged local shell access on a system with sudo installed to escalate their privileges to root on the system.