CVE-2019-18634

HIGH

Sudo <1.8.26 - Buffer Overflow

Title source: llm

Description

In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.

Exploits (18)

exploitdb WORKING POC
by Dylan Katz · bashlocallinux
https://www.exploit-db.com/exploits/48052
exploitdb WORKING POC
by Joe Vennix · textdoslinux
https://www.exploit-db.com/exploits/47995
github WORKING POC 690 stars
by lockedbyte · cpoc
https://github.com/lockedbyte/CVE-Exploits/tree/master/CVE-2019-18634
nomisec WORKING POC 234 stars
by saleemrashid · poc
https://github.com/saleemrashid/sudo-cve-2019-18634
nomisec WORKING POC 58 stars
by Plazmaz · poc
https://github.com/Plazmaz/CVE-2019-18634
nomisec WORKING POC 5 stars
by aesophor · poc
https://github.com/aesophor/CVE-2019-18634
nomisec WORKING POC 2 stars
by chanbakjsd · poc
https://github.com/chanbakjsd/CVE-2019-18634
nomisec WORKING POC 2 stars
by N1et · poc
https://github.com/N1et/CVE-2019-18634
nomisec WORKING POC 1 stars
by ptef · poc
https://github.com/ptef/CVE-2019-18634
nomisec WRITEUP
by CyrusRazavi · poc
https://github.com/CyrusRazavi/CVE-2019-18634-writeup
nomisec STUB
by letsr00t · poc
https://github.com/letsr00t/-CVE-2019-18634-sudo-pwfeedback
nomisec WORKING POC
by ngyinkit · poc
https://github.com/ngyinkit/cve-2019-18634
nomisec WORKING POC
by l0w3 · poc
https://github.com/l0w3/CVE-2019-18634
nomisec WORKING POC
by DDayLuong · poc
https://github.com/DDayLuong/CVE-2019-18634
nomisec WORKING POC
by TheJoyOfHacking · poc
https://github.com/TheJoyOfHacking/saleemrashid-sudo-cve-2019-18634
nomisec WORKING POC
by paras1te-x · poc
https://github.com/paras1te-x/CVE-2019-18634
nomisec WORKING POC
by edsonjt81 · poc
https://github.com/edsonjt81/sudo-cve-2019-18634

References (26)

... and 6 more

Scores

CVSS v3 7.8
EPSS 0.8747
EPSS Percentile 99.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (4)
debian/debian_linux 8.0
debian/debian_linux 9.0
debian/debian_linux 10.0
sudo_project/sudo 1.7.1 - 1.8.26
Published Jan 29, 2020
Tracked Since Feb 18, 2026