Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-3916

Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.023
EPSS Ranking 83.9%
CVSS Severity
CVSS v2 Score 9.3
References
Products affected by CVE-2008-3916
  • Gnu » Ed » Version: 0.2
    cpe:2.3:a:gnu:ed:0.2
  • Gnu » Ed » Version: 0.3
    cpe:2.3:a:gnu:ed:0.3
  • Gnu » Ed » Version: 0.4
    cpe:2.3:a:gnu:ed:0.4
  • Gnu » Ed » Version: 0.5
    cpe:2.3:a:gnu:ed:0.5
  • Gnu » Ed » Version: 0.6
    cpe:2.3:a:gnu:ed:0.6
  • Gnu » Ed » Version: 0.7
    cpe:2.3:a:gnu:ed:0.7
  • Gnu » Ed » Version: 0.8
    cpe:2.3:a:gnu:ed:0.8
  • Gnu » Ed » Version: 0.9
    cpe:2.3:a:gnu:ed:0.9


Contact Us

Shodan ® - All rights reserved