CVE-2002-0184
HIGHsudo < 1.6.6 - Heap-Based Buffer Overflow via Prompt Argument Expansion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-0184. PoCs published by MaXX.
AI-analyzed exploit summary This exploit leverages a heap overflow in Sudo's password prompt feature to achieve local privilege escalation. It manipulates heap metadata to overwrite a function pointer, leading to arbitrary code execution as root.
Description
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.
Exploits (1)
This exploit leverages a heap overflow in Sudo's password prompt feature to achieve local privilege escalation. It manipulates heap metadata to overwrite a function pointer, leading to arbitrary code execution as root.
References (14)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H