| Main Archive Page > Month Archives > full-disclosure-uk archives |
Summary
A vulnerability was reported in GNU ed. A remote user can cause arbitrary code to be executed on the target user's system.
Description
A remote user can create a specially crafted file that, when processed by the target user, will trigger a heap overflow and potentially execute arbitrary code on the target system. The code will run with the privileges of the target user.
The vulnerability resides in strip_escapes() in signal.c.
Note: This vulnerability found by Alfredo Ortega from Core Security Technologies.
Affected packages:
Pardus 2008:
ed, all before 1.0-9-2
Pardus 2007:
ed, all before 1.0-7-8
Resolution
There are update(s) for ed. You can update them via Package Manager or with a single command from console:
Pardus 2008:
pisi up ed
Pardus 2007:
pisi up ed
References