HomeFreeBSD

Fix shell injection vulnerability in patch(1) via ed(1) by

Description

Fix shell injection vulnerability in patch(1) via ed(1) by
tightening sanity check of the input. [1]

While I'm there also replace ed(1) with red(1) because we do
not need the unrestricted functionality. [2]

Obtained from: Bitrig [1], DragonFly [2]
Security: CVE-2015-1418 [1]

Details

Provenance
delphijAuthored on Aug 5 2015, 10:04 PM
Parents
rGf2a20b166a1e: Relax serialization of SYNCHRONIZE CACHE commands.
Branches
Unknown
Tags
Unknown

Event Timeline