Forum Discussion
CVE-2021-3156 | SUDO Heap-based Buffer Overflow
F5s seems to be vulnerable, to confirm, see below:
How can I test if I have vulnerable version?
To test if a system is vulnerable or not, login to the system as a non-root user.
Run command “sudoedit -s /”
If the system is vulnerable, it will respond with an error that starts with “sudoedit:”
If the system is patched, it will respond with an error that starts with “usage:”
Thanks for the reply, that's interesting. My BIG-IP (15.1.04) instances return:
sudoedit: command not found
Running an rpm -qa query also doesn't show sudo being installed. Could sudo be installed on some versions and not others?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
