CVE-2019-18634 is a stack-based buffer overflow in sudo’s password input handling, affecting sudo 1.7.1 through 1.8.30 when the pwfeedback option is enabled in sudoers. The flaw is in getln() in tgetpass.c. When pwfeedback is active, sudo prints and erases feedback characters during password entry. Under specific error conditions, pwfeedback is not properly disabled when input is read from a non-terminal source, and after a write error while erasing feedback asterisks, the code resets the remaining buffer length but fails to correctly reset the buffer position. As a result, subsequent input handling can write past the end of a stack buffer. The issue can be triggered by supplying a long string to stdin, including reproduction cases involving embedded terminal kill characters and a pseudo-terminal that cannot be written to; for older versions prior to 1.8.26, piped input with NUL kill characters was sufficient.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This repository contains a local privilege escalation exploit for CVE-2019-18634, a vulnerability in sudo (with pwfeedback enabled). The main file, 'exploit.py', is a Python script that leverages the vulnerability to execute a reverse shell as root. The script creates a bash reverse shell script at '/tmp/shell.sh', sets it as executable, and uses it as the SUDO_ASKPASS helper to gain root privileges. The exploit listens on localhost:4444 for the reverse shell connection. The repository is simple, with only a README and the exploit script. The exploit is operational and demonstrates a working privilege escalation attack, but is not weaponized for remote or automated targeting. No external network endpoints are used; all actions are local to the compromised system.
This repository contains a single C exploit (exploit.c) targeting CVE-2019-18634, a local privilege escalation vulnerability in sudo when the pwfeedback option is enabled. The exploit works by creating a pseudo-terminal, crafting a buffer overflow payload, and manipulating sudo's internal structures to escalate privileges and execute a shell as root. The exploit is operational and requires compilation and execution on a vulnerable Linux system. The Makefile provides a simple build process, and the README references the CVE and relevant advisories. The exploit does not target remote systems or network services; it is strictly a local privilege escalation tool. Notable fingerprintable endpoints include /proc/self/exe (used to set SUDO_ASKPASS) and /dev/tty (referenced in comments).
This repository demonstrates a local privilege escalation exploit for CVE-2019-18634, targeting sudo version 1.8.25 with the 'pwfeedback' option enabled. The structure includes a Dockerfile to build a vulnerable Ubuntu 20.04 environment, a custom sudoers file enabling the vulnerable option, and an exploit script (exploit.py) written in Python. The exploit works by crafting a buffer overflow payload that manipulates internal sudo structures, ultimately allowing the attacker to execute arbitrary commands as root. The develop.sh script automates the Docker build and assists in analyzing the vulnerable sudo binary. The exploit is a proof-of-concept and requires local access to the system with the specific vulnerable configuration. No network endpoints are involved; the attack vector is purely local. The repository is well-structured for educational and demonstration purposes.
This repository provides a functional local privilege escalation exploit for CVE-2019-18634, a heap buffer overflow in sudo (<=1.8.30) when 'pwfeedback' is enabled. The exploit consists of a self-contained Bash script ('self-contained.sh') that orchestrates the attack, as well as its component scripts in the 'src' directory: a C program ('exec.c') that creates a SUID root shell, a Perl script ('xpl.pl') that crafts the malicious input to trigger the overflow, and a Bash runner ('run.sh'). The exploit uses 'socat' to create a pseudo-terminal, sets up the environment to use the malicious binary as SUDO_ASKPASS, and then triggers sudo to execute the payload, resulting in a root shell. The exploit is operational and requires local access to the target system. Key fingerprintable endpoints include temporary files in /tmp, the use of /proc/self/exe, and the download of a static socat binary from GitHub.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.