Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 04 Sep 2008 22:44:47 +0200
From: Florian Weimer <fw@...eb.enyo.de>
To: oss-security@...ts.openwall.com
Subject: Re: GNU ed heap overflow

* Steven M. Christey:

> On Mon, 1 Sep 2008, Florian Weimer wrote:
>
>> Interesting.  But this type of command execution is not possible with
>> "red", which suffers from the same overflow.
>
> Does red share the same codebase as ed?  Or is a separate CVE necessary?

lrwxrwxrwx 1 root root 7 2008-08-31 11:36 /usr/bin/red -> /bin/ed

It's "restricted ed" in the sense of "restriced bash" etc.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.