
CVE-2021-3156
Heap-based buffer overflow in Sudo (CVE-2021-3156)
Heap overflow vulnerability caused by improper escaping of \ in sudo, LPE
All versions from 1.8.2 to 1.8.31p2
All stable versions from 1.9.0 to 1.9.5p1
sudoedit -s '\' `perl -e 'print "A" x 65536'
If output similar to Segmentation fault (core dumped) appears, the vulnerability exists.
https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt
Placeholder, currently debugging and analyzing. Link to blog will be posted after analysis is complete.