The attached is a nice explanation of the “sudo” bug, but somehow I feel that it would be better coming from @XKCD

The Qualys Research Team has discovered a heap overflow vulnerability in sudo, a near-ubiquitous utility available on major Unix-like operating systems. Any unprivileged user can gain root privileges on a vulnerable host using a default sudo configuration by exploiting this vulnerability…

https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *