9.3
CVSSv2

CVE-2008-3916

Published: 04/09/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed prior to 1.0 allows context-dependent or user-assisted malicious users to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu ed 0.7

gnu ed 0.8

gnu ed 0.5

gnu ed 0.6

gnu ed 0.3

gnu ed 0.4

gnu ed 0.2

gnu ed 0.9

Vendor Advisories

Synopsis Moderate: ed security update Type/Severity Security Advisory: Moderate Topic An updated ed package that fixes one security issue is now available forRed Hat Enterprise Linux 21, 3, 4 and 5This update has been rated as having moderate security impact by the RedHat Security Response Team ...