Baron Samedit
CVE-2021β3156
Last updated
CVE-2021β3156
Last updated
The "Sudo Baro Samedit" is heap buffer overflow exploit allowing any user to escalate privileges to root. No misconfigurations required, this exploit works with the default settings, for any user regardless of Sudo permissions.
The vulnerability was patched, but it didnβt update the version number for sudo or any other binary. So itβs not possible to tell definitively if a version if vulnerable or not just by version number.It can affects any unpatched version of the sudo program from 1.8.2β1.8.31p2 and 1.9.0β1.9.5p1
To check the exploitability of sudo, you may run the following commands. If it's returns the sudoedit: /: not a regular file
error message, then itβs vulnerable. If it returns the sudoedit usage, itβs not.
Or with the following command, if the system is vulnerable it will overwrite the heap buffer and crash the process: