Stack-based buffer overflow in Sudo - CVE-2019-18634

 

Stack-based buffer overflow in Sudo - CVE-2019-18634

Published: January 31, 2020 / Updated: August 1, 2021


Vulnerability identifier: #VU24810
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-18634
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the getln() function in tgetpass.c, if pwfeedback is enabled in /etc/sudoers. A local user can trigger stack-based buffer overflow and execute arbitrary code on the target system with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Sudo
Traffix SDC
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Data Computing Appliance (DCA)
Arch Linux
Amazon Linux AMI
Gentoo Linux
CentOS
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
sudo (Alpine package)
sudo (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
sudo
Juniper Junos Space

How to mitigate CVE-2019-18634

Install updates from vendor's website.

Sudo - update to 1.8.31
sudo (Alpine package) - addressed in versions 1.8.29-r2, 1.8.31-r0
sudo (Debian package) - update to 1.8.19p1-2.1+deb9u2
sudo - addressed in versions 1.9.0-0.1.b1.fc31, 1.9.0-0.1.b1.fc32
Data Computing Appliance (DCA) - update to 4.3.0.0
Juniper Junos Space - update to 20.3R1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins