Gentoo Security Advisory GLSA 200410-07 (ed)

Summary
The remote host is missing updates announced in advisory GLSA 200410-07.
Solution
All ed users should upgrade to the latest version: # emerge sync # emerge -pv '>=sys-apps/ed-0.2-r4' # emerge '>=sys-apps/ed-0.2-r4' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200410-07 http://bugs.gentoo.org/show_bug.cgi?id=66400
Insight
The ed utility is vulnerable to symlink attacks, potentially allowing a local user to overwrite or change rights on arbitrary files with the rights of the user running ed, which could be the root user.