Forum Discussion
CVE-2021-3156 | SUDO Heap-based Buffer Overflow
F5s seems to be vulnerable, to confirm, see below:
How can I test if I have vulnerable version?
To test if a system is vulnerable or not, login to the system as a non-root user.
Run command “sudoedit -s /”
If the system is vulnerable, it will respond with an error that starts with “sudoedit:”
If the system is patched, it will respond with an error that starts with “usage:”
- Barny_RichesJan 27, 2021
Altostratus
Thanks for the reply, that's interesting. My BIG-IP (15.1.04) instances return:
sudoedit: command not found
Running an rpm -qa query also doesn't show sudo being installed. Could sudo be installed on some versions and not others?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com