Skip to content

LockedByte Blog

Exploiting and vulnerability analysis
  • Home
  • CTF Writeups
  • Vulnerabilities
  • Malware
  • Contact

Month: February 2021

CVE-2021-3156 – sudo heap-based overflow leading to privilege escalation (PoC development)

Posted on February 19, 2021February 20, 2021 by lockedbyte

On 26th of January, a new sudo vulnerability came out reported by Qualys (Baron Samedit).

The advisory is available here.

The vulnerability is present in the sudo code for 10 years, which attracts a lot, as a ton sudo versions are affected.

Continue reading
Posted in vulnerabilities

About this blog

This is just a basic blog where I plan to post about CVE analysis and exploitation, writeups for CTF challenges I find interesting, all mainly related to binary exploitation and low-level vulnerabilities.

Search

Recent Posts

  • Having fun with a Use-After-Free in ProFTPd (CVE-2020-9273)
  • From theory to practice: analysis and PoC development for CVE-2020-28018 (Use-After-Free in Exim)
  • CVE-2021-3156 – sudo heap-based overflow leading to privilege escalation (PoC development)
  • Java decompiler (jad) 1.5.8e – Stack-based buffer overflow analysis and PoC
  • CVE-2019-18634 OOB write – analysis and development of a working PoC

Sorted posts

  • August 2021
  • May 2021
  • February 2021
  • December 2020
  • November 2020
  • October 2020

Calendar

February 2021
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
« Dec   May »

Privacy Policy

Check the privacy policy here.

Proudly powered by WordPress