Lucene search

K
osvGoogleOSV:RLSA-2020:4453
HistoryNov 03, 2020 - 12:06 p.m.

Moderate: vim security update

2020-11-0312:06:10
Google
osv.dev
16
vim
vi editor
security update
arbitrary os commands
scripting interfaces
cve-2019-20807
rocky linux 8.3 release notes

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

17.8%

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

  • vim: users can execute arbitrary OS commands via scripting interfaces in the rvim restricted mode (CVE-2019-20807)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.3 Release Notes linked from the References section.