PT-2008-4157 · Vim+1 · Vim+1

Jan Minar

·

Publicado

2008-06-16

·

Atualizado

2018-11-01

·

CVE-2008-2712

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vim versions prior to 7.1.314
Description The issue allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions. This can be demonstrated using various scripts such as filetype.vim, xpm.vim, gzip vim, and netrw.
Recommendations For versions prior to 7.1.314, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict the use of potentially vulnerable scripts until a patch is available. Avoid using the execute or system functions with unsanitized inputs in Vim scripts.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2712
DSA-1733-1
DTSA-143-1
RHSA-2008:0580
RHSA-2008:0617
RHSA-2008:0618
RHSA-2008_0580
RHSA-2008_0617

Produtos afetados

Red Hat
Vim