|
Vim / Gvim Modelines Command Execution Vulnerabilities
|
|
Secunia Advisory:
|
SA13490
|
|
|
Release Date:
|
2004-12-16
|
|
Popularity:
|
12,808 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Privilege escalation
|
|
Where:
|
Local system
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | GVim 6.x Vim 6.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2004-1138
|
|
Description: Ciaran McCreesh has reported some vulnerabilities in vim and gvim, which can be exploited by malicious, local users to gain escalated privileges.
The vulnerabilities are caused due to some errors in the modelines options. This can be exploited to execute shell commands when a malicious file is opened.
Successful exploitation can lead to escalated privileges but requires that modelines is enabled.
Solution: Apply patch for vim 6.3:
ftp://ftp.vim.org/pub/vim/patches/6.3/6.3.045
Provided and/or discovered by: Ciaran McCreesh
Original Advisory: http://www.gentoo.org/security/en/glsa/glsa-200412-10.xml
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|