• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

Syriel

Banned
Dec 13, 2017
11,088


CVE-2021-3156 also impacts @apple MacOS Big Sur (unpatched at present), you can enable exploitation of the issue by symlinking sudo to sudoedit and then triggering the heap overflow to escalate one's privileges to 1337 uid=0. Fun for @p0sixninja

EtPFrOJXIAAKe4i




Sudo has released an advisory addressing a heap-based buffer overflow vulnerability—CVE-2021-3156—affecting sudo legacy versions 1.8.2 through 1.8.31p2 and stable versions 1.9.0 through 1.9.5p1. Sudo is a utility included in many Unix- and Linux-based operating systems that allows a user to run programs with the security privileges of another user. An attacker could exploit this vulnerability to take control of an affected system.

CISA encourages users and administrators to update to sudo version 1.9.5p2, refer to vendors for available patches, and review the following resources for additional information.

 

Deleted member 15476

User requested account closure
Banned
Oct 27, 2017
5,268
It has already been patched on all major Linux Distros. Apple will probably follow suit sooner than later.
 
Oct 25, 2017
3,722
Looks like the only requirement for this is to have permissions for symlinking and access to a shell.

Not the easiest thing to exploit, but if you do it, you'll have the whole computer.