Sploitus

Exploit for Off-by-one Error in Sudo Project Sudo

githubexploit Β· 2021-01-31

Exploit Code

README5 lines
## https://sploitus.com/exploit?id=C7EFCE12-F44C-5E4A-8D51-D4F6CE4A377D
# CVE-2021-3156
Description
Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
![immagine](https://user-images.githubusercontent.com/56889513/117021357-9284ac00-acf7-11eb-9bce-a5ee97461958.png)