<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:35:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-00364</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-00364</link>
      <description>bdu:2021-00364</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-00364</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-3156 — CVE-2021-3156 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-3156</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-3156</guid>
    </item>
    <item>
      <title>certfr-2021-avi-063 — Une vulnérabilité a été découverte dans Sudo. Elle permet à un attaquant
de provoquer une élévation de privilèges. Les…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-063</link>
      <description>certfr-2021-avi-063</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-063</guid>
    </item>
    <item>
      <title>cisco-sa-sudo-privesc-jan2021-qnYQfcM — Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-sudo-privesc-jan2021-qnyqfcm</link>
      <description>&lt;p&gt;A vulnerability in the command line parameter parsing code of Sudo could allow an authenticated, local attacker to execute commands or binaries with root privileges.&#13;
&#13;
The vulnerability is due to improper parsing of command line parameters that may result in a heap-based buffer overflow. An attacker could exploit this vulnerability by accessing a Unix shell on an affected device and then invoking the sudoedit command with crafted parameters or by executing a binary exploit. A successful exploit could allow the attacker to execute commands or binaries with root privileges.&#13;
&#13;
This advisory is available at the following link:&#13;
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM&amp;#34;]&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the command line parameter parsing code of Sudo could allow an authenticated, local attacker to execute commands or binaries with root privileges.&#13;
&#13;
The vulnerability is due to improper parsing of command line parameters that may result in a heap-based buffer overflow. An attacker could exploit this vulnerability by accessing a Unix shell on an affected device and then invoking the sudoedit command with crafted parameters or by executing a binary exploit. A successful exploit could allow the attacker to execute commands or binaries with root privileges.&#13;
&#13;
This advisory is available at the following link:&#13;
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sudo-privesc-jan2021-qnYQfcM&amp;#34;]&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-sudo-privesc-jan2021-qnyqfcm</guid>
    </item>
    <item>
      <title>cnvd-2021-07130</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-07130</link>
      <description>cnvd-2021-07130</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-07130</guid>
    </item>
    <item>
      <title>EUVD-2026-256034</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-256034</link>
      <description>EUVD-2026-256034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-256034</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3156</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3156</link>
      <description>&lt;p&gt;Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3156</guid>
    </item>
    <item>
      <title>GHSA-w5vh-2923-gp5c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w5vh-2923-gp5c</link>
      <description>&lt;p&gt;Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character:&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character:&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w5vh-2923-gp5c</guid>
    </item>
    <item>
      <title>gsd-2021-3156</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3156</link>
      <description>gsd-2021-3156</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3156</guid>
    </item>
    <item>
      <title>ICSA-21-119-03 — Johnson Controls Exacq Technologies exacqVision</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-119-03</link>
      <description>&lt;p&gt;The affected product calculates or uses an incorrect maximum or minimum value that is one more or one less than the correct value.CVE-2021-3156 has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected product calculates or uses an incorrect maximum or minimum value that is one more or one less than the correct value.CVE-2021-3156 has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-119-03</guid>
    </item>
    <item>
      <title>OESA-2021-1002 — sudo security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1002</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: sudo, openEuler:20.03-LTS-SP1: sudo&lt;/p&gt;
&lt;p&gt;A flaw was found in sudo. A heap-based buffer overflow was found in the way sudo parses command line arguments. This flaw is exploitable by any local user (normal users and system users, sudoers and non-sudoers), without authentication (i.e., the attacker does not need to know the user&amp;#39;s password). Successful exploitation of this flaw could lead to privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2021-3156)\r\n\r\n
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.(CVE-2021-23239)\r\n\r\n
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.(CVE-2021-23240)\r\n\r\n&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: sudo, openEuler:20.03-LTS-SP1: sudo&lt;/p&gt;
&lt;p&gt;A flaw was found in sudo. A heap-based buffer overflow was found in the way sudo parses command line arguments. This flaw is exploitable by any local user (normal users and system users, sudoers and non-sudoers), without authentication (i.e., the attacker does not need to know the user&amp;#39;s password). Successful exploitation of this flaw could lead to privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2021-3156)\r\n\r\n
The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.(CVE-2021-23239)\r\n\r\n
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.(CVE-2021-23240)\r\n\r\n&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1002</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0169-1 — Security update for sudo</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0169-1</link>
      <description>&lt;p&gt;Security update for sudo&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for sudo&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0169-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0219 — Red Hat Security Advisory: sudo security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0219</link>
      <description>&lt;p&gt;sudo: Heap buffer overflow in argument parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sudo: Heap buffer overflow in argument parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0219</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:0225-1 — Security update for sudo</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:0225-1</link>
      <description>&lt;p&gt;Security update for sudo&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for sudo&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:0225-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3156</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3156</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: sudo, Ubuntu:16.04:LTS: sudo, Ubuntu:18.04:LTS: sudo, Ubuntu:20.04:LTS: sudo&lt;/p&gt;
&lt;p&gt;Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: sudo, Ubuntu:16.04:LTS: sudo, Ubuntu:18.04:LTS: sudo, Ubuntu:20.04:LTS: sudo&lt;/p&gt;
&lt;p&gt;Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3156</guid>
    </item>
    <item>
      <title>VDE-2021-011 — TRUMPF Laser GmbH: TruControl 2.14.0 to 3.14.0 affected by recent sudo vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-011</link>
      <description>&lt;p&gt;TruControl laser control software from versions 2.14.0 to 3.14.0 use sudo versions affected by CVE-2021-3156. The affected sudo has a heap-based buffer overflow, allowing privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TruControl laser control software from versions 2.14.0 to 3.14.0 use sudo versions affected by CVE-2021-3156. The affected sudo has a heap-based buffer overflow, allowing privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-011</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0066 — sudo: Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0066</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in sudo ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in sudo ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0066</guid>
    </item>
  </channel>
</rss>
