PT-2016-4670 · Vim+5 · Vim+5

Bram Moolenaar

+1

·

Published

2016-11-22

·

Updated

2022-12-27

·

CVE-2016-1248

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vim versions prior to 8.0.0056
Description The issue arises from improper validation of values for the filetype, syntax, and keymap options. This can lead to the execution of arbitrary code when a file with a specially crafted modeline is opened.
Recommendations For versions prior to 8.0.0056, update to a version that includes patch 8.0.0056 or later to resolve the issue.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2338
CESA-2016_2972
CVE-2016-1248
DLA-718-1
DSA-3722-1
MGASA-2017-0275
OPENSUSE-SU-2016_2992-1
OPENSUSE-SU-2016_2993-1
RHSA-2016:2972
RHSA-2016_2972
SUSE-SU-2016:2938-1
SUSE-SU-2016:2942-1
SUSE-SU-2016_2938-1
SUSE-SU-2016_2942-1
SUSE-SU-2022:4619-1
USN-3139-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Vim