Stack-based buffer overflow in Sudo - CVE-2019-18634
Published: January 31, 2020 / Updated: August 1, 2021
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the getln() function in tgetpass.c, if pwfeedback is enabled in /etc/sudoers. A local user can trigger stack-based buffer overflow and execute arbitrary code on the target system with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Traffix SDC
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Data Computing Appliance (DCA)
Arch Linux
Amazon Linux AMI
Gentoo Linux
CentOS
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
sudo (Alpine package)
sudo (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
sudo
Juniper Junos Space
How to mitigate CVE-2019-18634
sudo (Alpine package) - addressed in versions 1.8.29-r2, 1.8.31-r0
sudo (Debian package) - update to 1.8.19p1-2.1+deb9u2
sudo - addressed in versions 1.9.0-0.1.b1.fc31, 1.9.0-0.1.b1.fc32
Data Computing Appliance (DCA) - update to 4.3.0.0
Juniper Junos Space - update to 20.3R1
Links to Public Exploits and PoC-codes
- Exploit #6588 - CVE-2019-18634 (My n-day exploit for CVE-2019-18634 (local privilege escalation)) (August 1, 2021)
- Exploit #5789 - Sudo 1.8.25p - Buffer Overflow (June 17, 2021)
- Exploit #5408 - CVEPedia (A compilation of well-known CVEs and their one-liner ready to run.) (May 13, 2021)
- Exploit #5322 - CVE-2019-18634 (exploit) (April 28, 2021)
- Exploit #4937 - CVE-Exploits (PoC exploits for software vulnerabilities) (December 16, 2020)
- Exploit #4832 - CVE-2019-18634 (exploit for sudo CVE-2019-18634) (November 12, 2020)
- Exploit #2236 - SUDO_KILLER (A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regu (March 26, 2020)
- Exploit #2199 - CVE-2019-18634 (An Python Exploit for Sudo vulnerability CVE-2019-18634) (March 18, 2020)
- Exploit #290 - CVE-POCs (My attempt at writing exploit POCs for various CVEs) (March 18, 2020)
- Exploit #291 - CVE-2019-18634 (A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc) (March 18, 2020)
- Exploit #292 - CVE-2019-18634 (sudo exploit for CVE-2019-18634) (March 18, 2020)
External References
Related Security Bulletins
- Privilege escalation in Sudo
- Slackware Linux update for sudo
- Debian update for sudo
- Arch Linux update for sudo
- Red Hat update for sudo
- Red Hat update for sudo
- Red Hat update for sudo
- OpenSUSE Linux update for sudo
- Privilege escalation in sudo component in F5 Networks Traffix SDC
- Red Hat Enterprise Linux 6 update for sudo
- Gentoo update for sudo
- Amazon Linux AMI update for sudo
- CentOS 6 update for sudo
- CentOS 7 update for sudo
- Stack-based buffer overflow in sudo (Alpine package)
- Multiple vulnerabilities in Juniper Junos Space
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Fedora 31 update for sudo
- Fedora 32 update for sudo