Lucene search

K
ubuntuUbuntuUSN-463-1
HistoryMay 23, 2007 - 12:00 a.m.

vim vulnerability

2007-05-2300:00:00
ubuntu.com
48

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.018

Percentile

88.3%

Releases

  • Ubuntu 7.04
  • Ubuntu 6.10

Details

Tomas Golembiovsky discovered that some vim commands were accidentally
allowed in modelines. By tricking a user into opening a specially
crafted file in vim, an attacker could execute arbitrary code with user
privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu7.04noarchvim< 1:7.0-164+1ubuntu7.1UNKNOWN
Ubuntu6.10noarchvim< 1:7.0-035+1ubuntu5.1UNKNOWN

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.2

Confidence

Low

EPSS

0.018

Percentile

88.3%