sudo
before v1.9.5p2
has a Heap-based buffer overflow, allowing privilege escalation to root via sudoedit -s
and a command-line argument that ends with a single backslash character.
I'm wondering if it is enough to run:
sudo apt update
on a Ubuntu server to fix CVE-2021-3156
?
I've been doing some reading but I haven't found any concrete answer, I guess because it is a very recent issue.
Thanks you!
question from:https://stackoverflow.com/questions/65919828/how-to-fix-cve-2021-3156