PT-2008-4157 · Vim+1 · Vim+1

Jan Minar

·

Published

2008-06-16

·

Updated

2018-11-01

·

CVE-2008-2712

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vim versions prior to 7.1.314
Description The issue allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions. This can be demonstrated using various scripts such as filetype.vim, xpm.vim, gzip vim, and netrw.
Recommendations For versions prior to 7.1.314, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict the use of potentially vulnerable scripts until a patch is available. Avoid using the execute or system functions with unsanitized inputs in Vim scripts.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2712
DSA-1733-1
DTSA-143-1
RHSA-2008:0580
RHSA-2008:0617
RHSA-2008:0618
RHSA-2008_0580
RHSA-2008_0617

Affected Products

Red Hat
Vim