CVE-2008-3916

Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename.  NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
gnued
0.2
gnued
0.3
gnued
0.4
gnued
0.5
gnued
0.6
gnued
0.7
gnued
0.8
gnued
0.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ed
bullseye
1.17-1
fixed
etch
no-dsa
bookworm
1.19-1
fixed
sid
1.20.2-2
fixed
trixie
1.20.2-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ed
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
ignored
intrepid
ignored
hardy
ignored
gutsy
ignored
feisty
ignored
dapper
ignored
References