PT-2008-1077 · Gnu+1 · Ed+1

Published

2008-09-04

·

Updated

2018-10-11

·

CVE-2008-3916

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ed versions prior to 1.0
Description The issue is related to a heap-based buffer overflow in the strip escapes function in signal.c in GNU ed, which can be exploited by context-dependent or user-assisted attackers to execute arbitrary code via a long filename. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be carried out remotely.
Recommendations For versions prior to 1.0, update to version 1.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the strip escapes function in signal.c to minimize the risk of exploitation. Avoid using long filenames when invoking ed until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07195
BDU:2015-08455
BDU:2015-09356
CVE-2008-3916
RHSA-2008:0946
RHSA-2008_0946

Affected Products

Red Hat
Ed