|
Message-ID: <87zlmnabeo.fsf@mid.deneb.enyo.de> Date: Thu, 04 Sep 2008 22:44:47 +0200 From: Florian Weimer <fw@...eb.enyo.de> To: oss-security@...ts.openwall.com Subject: Re: GNU ed heap overflow * Steven M. Christey: > On Mon, 1 Sep 2008, Florian Weimer wrote: > >> Interesting. But this type of command execution is not possible with >> "red", which suffers from the same overflow. > > Does red share the same codebase as ed? Or is a separate CVE necessary? lrwxrwxrwx 1 root root 7 2008-08-31 11:36 /usr/bin/red -> /bin/ed It's "restricted ed" in the sense of "restriced bash" etc.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.