oss-sec mailing list archives
Re: CVE Id request: vim
From: Tomas Hoger <thoger () redhat com>
Date: Tue, 15 Jul 2008 11:00:27 +0200
On Mon, 16 Jun 2008 16:47:07 -0400 (EDT) "Steven M. Christey" <coley () linus mitre org> wrote:
In a perfect world, we'd know which Vim scripts were vulnerable in which version, but I don't see an easy way of determining that. So, only one CVE is being assigned for them, pending any additional details.
Let's push the world a bit towards "perfect" state ;) - zip.vim and tar.vim (omitted in the CVE description) only seem to be shipped with vim as of vim 7.0. 6.x versions of vim do not have them and can not be used to browse .zip/.tar archives. Affected in versions used in 7.0 and 7.1. I don't see them in 6.4 tarball, so no sure why advisory states 6.4 is not affected. 6.3 and 6.0 were verified to be unaffected. - netrw seems to be used as directory explorer as of vim 7.0. However, netrw test case triggers similar problem in explorer.vim plugin used in vim 6.x versions. So netrw test reports vulnerable for multiple versions back to 6.0 (tested on 7.1, 7.0, 6.3 and 6.0), even though different plugins are affected on 7.x and 6.x. - All other tests affect vim versions at least back to 6.0 (tested on versions listed above).
====================================================== Name: CVE-2008-2712 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2712 Reference: BUGTRAQ:20080613 Collection of Vulnerabilities in Fully Patched Vim 7.1 Reference: URL:http://www.securityfocus.com/archive/1/archive/1/493352/100/0/threaded Reference: BUGTRAQ:20080614 Re: Collection of Vulnerabilities in Fully Patched Vim 7.1 Reference: URL:http://www.securityfocus.com/archive/1/archive/1/493353/100/0/threaded Reference: MISC:http://www.rdancer.org/vulnerablevim.html Reference: MLIST:[oss-security] CVE Id request: vim Reference: URL:http://www.openwall.com/lists/oss-security/2008/06/16/2 Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (2) zipplugin, (3) xpm.vim, (4) gzip_vim, and (5) netrw.
-- Tomas Hoger / Red Hat Security Response Team
Current thread:
- Re: CVE Id request: vim Tomas Hoger (Jul 15)