FreeBSD Security Advisory – patch Shell Injection

FreeBSD Security Advisory – Due to insufficient sanitization of the input patch stream, it is possible for a patch file to cause patch(1) to pass certain ed(1) scripts to the ed(1) editor, which would run commands.

Leave a Reply