Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| sudo_project | sudo | 1.8.2 - 1.8.32 | - |
| sudo_project | sudo | 1.9.0 - 1.9.5 | - |
| sudo_project | sudo | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
32
Affected Products
68
References
sudo_project / sudo
| - |
| sudo_project | sudo | - | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - | - |
| debian | debian_linux | - | - |
| debian | debian_linux | - | - |
| netapp | active_iq_unified_manager | - | - |
| netapp | cloud_backup | - | - |
| netapp | hci_management_node | - | - |
| netapp | oncommand_unified_manager_core_package | - | - |
| netapp | ontap_select_deploy_administration_utility | - | - |
| netapp | ontap_tools | - | - |
| netapp | solidfire | - | - |
| mcafee | web_gateway | - | - |
| mcafee | web_gateway | - | - |
| mcafee | web_gateway | - | - |
| synology | diskstation_manager_unified_controller | - | - |
| synology | diskstation_manager | - | - |
| synology | skynas_firmware | - | - |
| synology | vs960hd_firmware | - | - |
| beyondtrust | privilege_management_for_mac | 21.1.1 | - |
| beyondtrust | privilege_management_for_unix\/linux | 10.3.2-10 | - |
| oracle | micros_compact_workstation_3_firmware | - | - |
| oracle | micros_es400_firmware | 400 - 410 | - |
| oracle | micros_kitchen_display_system_firmware | - | - |
| oracle | micros_workstation_5a_firmware | - | - |
| oracle | micros_workstation_6_firmware | 610 - 655 | - |
| oracle | communications_performance_intelligence_center | 10.3.0.0.0 - 10.3.0.2.1 | - |
| oracle | communications_performance_intelligence_center | 10.4.0.1.0 - 10.4.0.3.1 | - |
| oracle | tekelec_platform_distribution | 7.4.0 - 7.7.1 | - |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability
Impact