diff --git a/chapter06/ed-exp.xml b/chapter06/ed-exp.xml index 0914671f5..41e4d35e4 100644 --- a/chapter06/ed-exp.xml +++ b/chapter06/ed-exp.xml @@ -1,8 +1,10 @@ Command explanations -The sed commands fix a symlink vulnerability in ed. See - -http://www.securityfocus.com/templates/advisory.html?id=3308 for -more information. +The sed commands fix a symlink vulnerability in ed. The ed +executable creates files in /tmp with predictable names. By using +various symlink attacks, it is possible to have ed write to files +it should not, change the permissions of various files, etc. + +