CVE-2008-3916

EUVD-2008-3901
Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename.  NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
gnued
0.2
gnued
0.3
gnued
0.4
gnued
0.5
gnued
0.6
gnued
0.7
gnued
0.8
gnued
0.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ed
bookworm
1.19-1
fixed
bullseye
1.17-1
fixed
etch
no-dsa
sid
1.20.2-2
fixed
trixie
1.20.2-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ed
dapper
ignored
feisty
ignored
gutsy
ignored
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
References