Lucene search

K
nvd[email protected]NVD:CVE-2008-4677
HistoryOct 22, 2008 - 6:00 p.m.

CVE-2008-4677

2008-10-2218:00:00
CWE-255
web.nvd.nist.gov
4

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.002

Percentile

61.4%

autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating “I’m assuming that they’re using the same id and password on that unchanged hostname, deliberately.”

Affected configurations

Nvd
Node
vimvimMatch7.1
OR
vimvimMatch7.1.266
OR
vimvimMatch7.2
AND
vimnetrwMatch109
OR
vimnetrwMatch110
OR
vimnetrwMatch111
OR
vimnetrwMatch112
OR
vimnetrwMatch113
OR
vimnetrwMatch114
OR
vimnetrwMatch115
OR
vimnetrwMatch116
OR
vimnetrwMatch118
OR
vimnetrwMatch120
OR
vimnetrwMatch121
OR
vimnetrwMatch122
OR
vimnetrwMatch123
OR
vimnetrwMatch128
OR
vimnetrwMatch131

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.1

Confidence

Low

EPSS

0.002

Percentile

61.4%