PT-2019-6248 · Vim+8 · Vim+8

Guilherme De Almeida Suckevicz

·

Published

2019-02-08

·

Updated

2022-09-01

·

CVE-2019-20807

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Vim versions prior to 8.1.0881
Description The issue is related to the lack of input sanitization in the Vim text editor, allowing an attacker to access confidential data, compromise its integrity, and cause a denial of service. In Vim, users can circumvent the restricted mode and execute arbitrary OS commands via scripting interfaces such as Python, Ruby, or Lua.
Recommendations For versions prior to 8.1.0881, update to version 8.1.0881 or later to resolve the issue. As a temporary workaround, consider restricting access to scripting interfaces like Python, Ruby, or Lua until a patch is applied.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2040
ALT-PU-2019-2042
BDU:2022-05913
CESA-2020_4453
CVE-2019-20807
DLA-2876-1
OPENSUSE-SU-2020:0794-1
OPENSUSE-SU-2020_0794-1
RHSA-2020:4453
RHSA-2020_4453
RLSA-2020:4453
SUSE-SU-2020:14385-1
SUSE-SU-2020:1550-1
SUSE-SU-2020:1551-1
SUSE-SU-2020_14385-1
SUSE-SU-2020_1550-1
SUSE-SU-2020_1551-1
USN-4582-1
USN-5147-1

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Vim