PT-2008-1077 · Gnu+1 · Ed+1

Publicado

2008-09-04

·

Atualizado

2018-10-11

·

CVE-2008-3916

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ed versions prior to 1.0
Description The issue is related to a heap-based buffer overflow in the strip escapes function in signal.c in GNU ed, which can be exploited by context-dependent or user-assisted attackers to execute arbitrary code via a long filename. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out remotely.
Recommendations For versions prior to 1.0, update to version 1.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the strip escapes function in signal.c to minimize the risk of exploitation. Avoid using long filenames when invoking ed until the issue is resolved.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07195
BDU:2015-08455
BDU:2015-09356
CVE-2008-3916
RHSA-2008:0946
RHSA-2008_0946

Produtos afetados

Red Hat
Ed