← Back to CVE List

CVE-2019-18634

Published: 2020-01-29T18:15Z
Last Modified: 2024-11-21T04:33Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt