LWN.net Logo

vim: arbitrary command execution

Package(s):gvim CVE #(s):CVE-2008-2712
Created:August 12, 2008 Updated:March 24, 2009
Description: From the CVE entry: Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (2) zipplugin, (3) xpm.vim, (4) gzip_vim, and (5) netrw.
Alerts:
SuSE SUSE-SR:2009:007 2009-03-24
Debian DSA-1733 2009-03-03
Ubuntu USN-712-1 2009-01-27
Mandriva MDVSA-2008:236-1 2008-12-08
Mandriva MDVSA-2008:236 2008-12-03
CentOS CESA-2008:0580 2008-11-26
CentOS CESA-2008:0617 2008-11-25
Red Hat RHSA-2008:0618-01 2008-11-25
Red Hat RHSA-2008:0617-01 2008-11-25
Red Hat RHSA-2008:0580-01 2008-11-25
rPath rPSA-2008-0247-1 2008-08-11

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds