CVE-2008-3916
published 2008-09-04CVE-2008-3916: Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.60%
88.1th percentile
Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ed | < ed 0.7-2 (bookworm) | ed 0.7-2 (bookworm) |
| gnu | ed | — | — |
| gnu | ed | — | — |
| gnu | ed | — | — |
| gnu | ed | — | — |
| gnu | ed | — | — |
| gnu | ed | — | — |
| gnu | ed | — | — |
| gnu | ed | — | — |
| gnu | ed | >= 0 < 0.7-2 | 0.7-2 |
| gnu | ed | >= 0 < 0.7-2 | 0.7-2 |
| gnu | ed | >= 0 < 0.7-2 | 0.7-2 |
| gnu | ed | >= 0 < 0.7-2 | 0.7-2 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j55v-8789-5phj: Heap-based buffer overflow in the strip_escapes function in signal
ghsa_unreviewed·2022-05-02
CVE-2008-3916 [HIGH] CWE-119 GHSA-j55v-8789-5phj: Heap-based buffer overflow in the strip_escapes function in signal
Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
OSV
CVE-2008-3916: Heap-based buffer overflow in the strip_escapes function in signal
osv·2008-09-04·CVSS 9.3
CVE-2008-3916 [CRITICAL] CVE-2008-3916: Heap-based buffer overflow in the strip_escapes function in signal
Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
Red Hat
ed: Heap-based buffer overflow (arb. code execution)
vendor_redhat·2008-06-30·CVSS 9.3
CVE-2008-3916 [CRITICAL] CWE-122 ed: Heap-based buffer overflow (arb. code execution)
ed: Heap-based buffer overflow (arb. code execution)
Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
Debian
CVE-2008-3916: ed - Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed b...
vendor_debian·2008·CVSS 9.3
CVE-2008-3916 [CRITICAL] CVE-2008-3916: ed - Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed b...
Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.
Scope: local
bookworm: resolved (fixed in 0.7-2)
bullseye: resolved (fixed in 0.7-2)
forky: resolved (fixed in 0.7-2)
sid: resolved (fixed in 0.7-2)
trixie: resolved (fixed in 0.7-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [F9]
bugzilla·2008-10-08·CVSS 9.3
CVE-2008-3916 [CRITICAL] CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [F9]
CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
ed-1.1-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/ed-1.1-1.fc9
---
ed-1.1-1.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/ed-1.1-1.fc8
---
ed-1.1-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
ed-1.1-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [Fdevel]
bugzilla·2008-10-08·CVSS 9.3
CVE-2008-3916 [CRITICAL] CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [Fdevel]
CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
fixed in ed-1.1-1.fc10, currently in dist-f10-updates-candidate. Asked vor F10 inclusion at https://fedorahosted.org/rel-eng/ticket/904
---
This bug appears to have been reported against 'rawhide' during the Fedora 10 development cycle.
Changing version to '10'.
More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping
---
This message is a reminder that Fedora 10 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 10. It is Fedora's polic
Bugzilla
CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [F8]
bugzilla·2008-10-08·CVSS 9.3
CVE-2008-3916 [CRITICAL] CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [F8]
CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution) [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
ed-1.1-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/ed-1.1-1.fc9
---
ed-1.1-1.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/ed-1.1-1.fc8
---
ed-1.1-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
ed-1.1-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution)
bugzilla·2008-09-17·CVSS 9.3
CVE-2008-3916 [CRITICAL] CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution)
CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution)
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3916 to
the following vulnerability:
Heap-based buffer overflow in the strip_escapes function in signal.c
in GNU ed before 1.0 allows context-dependent or user-assisted
attackers to execute arbitrary code via a long filename. NOTE: since
ed itself does not typically run with special privileges, this issue
only crosses privilege boundaries when ed is invoked as a third-party
component.
References:
http://lists.gnu.org/archive/html/bug-ed/2008-08/msg00000.html
http://marc.info/?l=oss-security&m=122018171619930&w=4
http://www.openwall.com/lists/oss-security/2008/08/31/1
http://www.openwall.com/lists/oss-security/2008/09/01/2
http://www.openwall.com/lists
http://lists.gnu.org/archive/html/bug-ed/2008-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://secunia.com/advisories/32349http://secunia.com/advisories/32460http://secunia.com/advisories/33005http://secunia.com/advisories/38794http://secunia.com/advisories/43068http://security.gentoo.org/glsa/glsa-200809-15.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-461.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:200http://www.redhat.com/support/errata/RHSA-2008-0946.htmlhttp://www.securityfocus.com/archive/1/501298/100/0/threadedhttp://www.securityfocus.com/bid/30815http://www.securitytracker.com/id?1020734http://www.vmware.com/security/advisories/VMSA-2009-0003.htmlhttp://www.vupen.com/english/advisories/2008/2642http://www.vupen.com/english/advisories/2008/3347http://www.vupen.com/english/advisories/2010/0528http://www.vupen.com/english/advisories/2011/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/44643https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10678https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00847.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00873.htmlhttp://lists.gnu.org/archive/html/bug-ed/2008-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000082.htmlhttp://secunia.com/advisories/32349http://secunia.com/advisories/32460http://secunia.com/advisories/33005http://secunia.com/advisories/38794http://secunia.com/advisories/43068http://security.gentoo.org/glsa/glsa-200809-15.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-461.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:200http://www.redhat.com/support/errata/RHSA-2008-0946.htmlhttp://www.securityfocus.com/archive/1/501298/100/0/threadedhttp://www.securityfocus.com/bid/30815http://www.securitytracker.com/id?1020734http://www.vmware.com/security/advisories/VMSA-2009-0003.htmlhttp://www.vupen.com/english/advisories/2008/2642http://www.vupen.com/english/advisories/2008/3347http://www.vupen.com/english/advisories/2010/0528http://www.vupen.com/english/advisories/2011/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/44643https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10678https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00847.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00873.html
2008-09-04
Published