Description
GNU ed before 0.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files, possibly in the open_sbuf function.
CVSS vector
AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4 Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-q7jc-952h-fjg4: GNU ed before 0↗2022-05-01 ▶ OSVCVE-2006-6939: GNU ed before 0↗2007-01-17 ▶ CVEListCVE-2006-6939: GNU ed before 0↗2007-01-17 ▶ 📋Vendor Advisories
2Red HatCVE-2006-6939 Insecure use of temporary file in ed↗2007-11-11 ▶ DebianCVE-2006-6939: ed - GNU ed before 0.3 allows local users to overwrite arbitrary files via a symlink ...↗2006 ▶ 💬Community
3BugzillaCVE-2006-6939 Insecure use of temporary file in ed↗2007-01-17 ▶ BugzillaCVE-2006-6939 Insecure use of temporary file in ed↗2007-01-17 ▶ BugzillaCVE-2006-6939 Insecure use of temporary file in ed↗2007-01-17 ▶