PT-2019-6248 · Vim+8 · Vim+8

·

CVE-2019-20807

·

Publicado

2019-02-08

·

Atualizado

2022-09-01

CVSS v3.1

5.3

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Vim versions prior to 8.1.0881
Description The issue is related to the lack of input sanitization in the Vim text editor, allowing an attacker to access confidential data, compromise its integrity, and cause a denial of service. In Vim, users can circumvent the restricted mode and execute arbitrary OS commands via scripting interfaces such as Python, Ruby, or Lua.
Recommendations For versions prior to 8.1.0881, update to version 8.1.0881 or later to resolve the issue. As a temporary workaround, consider restricting access to scripting interfaces like Python, Ruby, or Lua until a patch is applied.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2040
ALT-PU-2019-2042
BDU:2022-05913
CESA-2020_4453
CVE-2019-20807
DLA-2876-1
OPENSUSE-SU-2020:0794-1
OPENSUSE-SU-2020_0794-1
RHSA-2020:4453
RHSA-2020_4453
RLSA-2020:4453
SUSE-SU-2020:14385-1
SUSE-SU-2020:1550-1
SUSE-SU-2020:1551-1
SUSE-SU-2020_14385-1
SUSE-SU-2020_1550-1
SUSE-SU-2020_1551-1
USN-4582-1
USN-5147-1

Produtos afetados

Alt Linux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Vim