Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Welcome To Ask or Share your Answers For Others

Categories

0 votes
213 views
in Technique[技术] by (71.8m points)

ubuntu - How to fix CVE-2021-3156

sudo before v1.9.5p2 has a Heap-based buffer overflow, allowing privilege escalation to root via sudoedit -s and a command-line argument that ends with a single backslash character.

I'm wondering if it is enough to run:

sudo apt update

on a Ubuntu server to fix CVE-2021-3156?

I've been doing some reading but I haven't found any concrete answer, I guess because it is a very recent issue.

Thanks you!

question from:https://stackoverflow.com/questions/65919828/how-to-fix-cve-2021-3156

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome To Ask or Share your Answers For Others

1 Reply

0 votes
by (71.8m points)

You need to update APT's package list and then install the upgrade:

sudo apt-get update
sudo apt-get --only-upgrade install sudo

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
OGeek|极客中国-欢迎来到极客的世界,一个免费开放的程序员编程交流平台!开放,进步,分享!让技术改变生活,让极客改变未来! Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Click Here to Ask a Question

...