March 7, 2001

Advisory for joe

Author: JT Smith

From LWN.net: "The joe text editor looks for configuration files in the current
working directory, the user's home directory, and finally in /etc/joe.
A malicious user could create their own .joerc configuration file and
attempt to get other users to use it. If this were to happen, the user
could potentially execute malicious commands with their own user ID and
privileges. This update removes joe's ability to use a .joerc
configuration file in the current working directory."

Category:

  • Linux
Click Here!