From 7511586fd553898e8f6ffe1cb49a5b457f4289cc Mon Sep 17 00:00:00 2001 From: Gerard Beekmans Date: Thu, 9 Aug 2001 01:47:42 +0000 Subject: Better explanation than the previous url (easier to just read it than having to 'click away' git-svn-id: http://svn.linuxfromscratch.org/LFS/trunk/BOOK@951 4aa44e1e-78dd-0310-a6d2-fbcd4c07a689 --- chapter06/ed-exp.xml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) (limited to 'chapter06/ed-exp.xml') diff --git a/chapter06/ed-exp.xml b/chapter06/ed-exp.xml index 0914671f5..41e4d35e4 100644 --- a/chapter06/ed-exp.xml +++ b/chapter06/ed-exp.xml @@ -1,8 +1,10 @@ Command explanations -The sed commands fix a symlink vulnerability in ed. See - -http://www.securityfocus.com/templates/advisory.html?id=3308 for -more information. +The sed commands fix a symlink vulnerability in ed. The ed +executable creates files in /tmp with predictable names. By using +various symlink attacks, it is possible to have ed write to files +it should not, change the permissions of various files, etc. + + -- cgit v1.2.3-54-g00ecf