Baron Samedit / CVE-2021-3156 / Serious issue in sudo

A few hours ago, a security issue has been announced, related to the package sudo. The issue may allow a malicious local user to gain root access.

More details on :

https://www.sudo.ws/alerts/unescape_overflow.html

Debian already released a patch, so a regular system upgrade should do the trick. We recommend you to upgrade your setup as soon as possible. (It’s also important not just for your server but any personal linux machine you may have)

You can check you’re up to date with dpkg --list | grep sudo

You should see :

ii  sudo-ldap           1.8.27-1+deb10u3 

(note the 3 at the end)

10 Likes