PT-2008-5890 · Vim+1 · Vim+2

Jan Lieskovsky

·

Published

2008-10-22

·

Updated

2017-08-08

·

CVE-2008-4677

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions autoload/netrw.vim (aka the Netrw Plugin) versions prior to 133k for Vim 7.1 and 7.2
Description The issue allows remote FTP servers to obtain sensitive information by logging usernames and passwords when attempting to establish subsequent FTP sessions to servers on different hosts. This occurs because the software stores credentials for an FTP session and sends those credentials when attempting to establish subsequent FTP sessions.
Recommendations For versions prior to 133k, update to version 133k or later to resolve the issue. As a temporary workaround, consider restricting the use of the Netrw Plugin for FTP sessions to minimize the risk of exploitation. Avoid using the same username and password across different FTP servers until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4677
ECHO-221D-CEF9-D3F8

Affected Products

Debian
Netrw Plugin
Vim