HIGH

CVE-2019-18634

CVSS v3

7.8

HIGH

EPSS Score

88.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.

Technical details

Published
1/29/2020

Frequently asked questions

What is CVE-2019-18634?

In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.

Is CVE-2019-18634 actively exploited?

Active exploitation of CVE-2019-18634 has not been confirmed. The EPSS score is 88.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-18634?

CVE-2019-18634 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2019-18634 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.