PT-2008-4157 · Vim+1 · Vim+1
Jan Minar
·
Publicado
2008-06-16
·
Atualizado
2018-11-01
·
CVE-2008-2712
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 7.1.314
Description
The issue allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the
execute or system functions. This can be demonstrated using various scripts such as filetype.vim, xpm.vim, gzip vim, and netrw.Recommendations
For versions prior to 7.1.314, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict the use of potentially vulnerable scripts until a patch is available. Avoid using the
execute or system functions with unsanitized inputs in Vim scripts.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat
Vim